CapitalOne has the most secure password system(capitaloneonline.co.uk)
capitaloneonline.co.uk
CapitalOne has the most secure password system
https://www.capitaloneonline.co.uk/CapitalOne_Consumer/Login.do
11 comments
Ouch! This means that they are storing your original password in plaintext somewhere, and that is definitely NOT best practices!
Maybe it's only a hashed version of the characters? :P
I think it's important to call attention to these issues, but can we change the sarcastic title?
I see no reason to? This is a UK bank, not observing security, UK levels of sarcasm are entirely in order.
I remember awhile back I created a CapitalOne account and I put in a long password which it excepted, when I tried to login it wouldn't work, so I reset my password very carefully typing it. The password reset was successful, I tried to login and nope, didn't work. Third time reset I realised they have a max password length and were truncating my password as my original password was past their max length but would except, truncate without telling me and store it. This was the CapitalOne in the US.
That is going to make lastpass hard to use for the site.
Also, they don't support any kind of two-factor authentication, and have no plans to add that: https://twitter.com/AskCapitalOne/status/504679257239719938
Maybe they think 'tick the box' and 'enter character N from your password' are additional factors. :p
Fidelity's phone system lets you authenticate by typing your password on the phone keypad. On the plus side, this is probably the only time I've understood the technical reason behind a limited password alphabet.
In my experience, most UK banks do the same thing. Their excuse is that it prevents keylogger attacks. I do not know enough to say whether it's an acceptable trade-off or not.
Seeing as I've been the victim of a half dozen or so password leaks, one credit card clone, and not a single keylogger attack, I'd probably err on the side of secure password storage, but that's just me.
Meanwhile, users actually type full password into the username field so they find the required characters by index, then delete it before submitting the form.
HSBC has this: single-letters from your "secret word", in addition to an actual full passphrase.
Is there another step after this one? Or does this get you in?
Why would anyone think this was a good idea?
This is the definition of 'security theater': take off your shoes, spin around, hop on one foot. Many consumers mistake having to jump through hoops over a flaming pile of poo for 'more secure'. So it goes. :(
Edit: I'm a U.S. CapitalOne customer, and I just know that if they do that to my login, I will close my account faster than you can say, “Warning: do not tick”. Good security doesn't need to be a hassle. And I'm happy to find another company that actually understands that.
Edit: I'm a U.S. CapitalOne customer, and I just know that if they do that to my login, I will close my account faster than you can say, “Warning: do not tick”. Good security doesn't need to be a hassle. And I'm happy to find another company that actually understands that.
Honestly don't all of the US banking and credit card companies do this sort of 'security theater'? While this seems pretty absurd, I'm not aware of any that don't have mediocore to poor password practices.
Simple.com is pretty awesome. I'm sure there are others as well, but yes -- they are in the minority. :/