We live in an age where this should be unacceptable. Why aren't there financial security laws yet?
I don't think banks actually care about individual user login security too much. Credit Cards reallllly suffer from security breaches though
But the only reason that banks care so much about credit-card security breaches is that the law forces them to do so. If the law didn't make credit card fraud the bank's responsibility, then they'd be just as lackluster about preventing it as they currently are about securing login credentials.
Remember when you couldn't take your cell phone number with you and so pretty much nobody switched carriers? It was a massive pain. Now it's easier than ever to switch, except most people are locked into multi-year contracts. Switching friction = high, but not impossible. As you said, TMO is trying to compete here.
Cable has monopolies on towns, so there's 0 incentive. People couldn't switch even if they wanted to. I suppose there's satellite, but you'll still be paying the cable company for internet -- they get their pound of flesh no matter what. Switching friction = impossible.
https://paragonie.com/blog/2015/08/you-wouldnt-base64-a-pass...
Furthermore, credit unions can't make risky bets that could put them under. The money you deposit goes out as loans to other people.
I avoid banks like the plague. Too shady for me, never again.
The operator on the line asked me a ton of questions starting from my user-id (but not password), date of birth, full name, father's name, place of birth, type of account and many others that I don't remember now. Only after I correctly answered all these questions, did he start acting on my instructions.
But if i tell them to not make it that easy, i cant manage my shit over the phone anymore :/
Where did you spend your honeymoon? What was the name of your first pet? What is the name of the street where you grew up?
For any given person, a LOT of people know the answer to these kind of questions.
Also, I hate it when people use date of birth to verify identity. Medical people love doing this. Um, just check the person's Facebook and see when everyone wishes them a happy birthday, then go access their medical records?
answer = PBKDF2(hmacsha1, password + question, "", 100000, 16)
This is also incidentally the basis for how I generate unique passwords for every service except banks, communication, and other sensitive things. I want a different password on every website and don't want to trust any password-remembering software I didn't write. The same function works fine for generating answers to secret questions.By that, I mean the overall security of your password scheme is analogous to what people get out of a password manager.
Still, a lot better than password re-use.
KeePass? It's great, and open source.
It's not quite as bad as asking "what species was your first pet?" but not much better.
This is the real problem with security questions; the answer space is often so very small, and can be narrowed down even further with a little research.
Questions like "what was the first name of (your maternal grandmother, your first best friend, etc.)" are very common -- well, there are stats on most popular first names of given generations in different places. If you know what country the person is in, you can make a good guess at these.
Tangential to the actual issue, but in that field it's to prevent patient mixups, not to defend against malicious attackers.
As you implicitly point out, however, it doesn't require any portion of the password ever to be visible to the call-centre employee; one can just supplement an individual hash by a collection of hashes of appropriate character subsets, and then (say) randomly pick among the available subsets.
I went to my boss and explained that we can't do that. It's inviting exploitation. He responded to me that we had to keep them in plain text, in the database so that we could send them to users who forgot. If they can't login, they won't order product.
I have heard similar stories from other IT professionals. It's amazing that these operations aren't getting pwn3d twice a week.
Seems that they don't have any other way to grant the technicians access to the server/my account, which is absolutely ridiculous.