logoalt Hacker News

tuetuopayyesterday at 6:31 PM3 repliesview on HN

That's without considering a lot of banks have non-textual inputs for their passwords. Man they love their scrambled virtual keyboard!

I think the worst I ever had was HSBC that asked me for fragments of my password, like characters 4, 6, 7, 11, and 12. Absolute bonkers of a security theatre.


Replies

weird-eye-issuetoday at 12:50 AM

Oh I've never seen anything like that. But it would still help because my password manager pops up matching logins so you could just open that manually and then copy paste parts of it or type it in.

shermantanktopyesterday at 9:13 PM

Had a similar UK bank experience. Without knowing it would be used for that, I had created a password that had digits. So "What's the 4th character" would be something like "6," "What's the 6th digit" would be "2," like an Abbott and Costello routine.

srdjanrtoday at 12:21 PM

How can they even do that without storing plaintext passwords?

show 1 reply