https://www.ft.com/content/33503e4a-8f95-11e6-a72e-b428cb934...
I do, and it's not fun when I get asked to type in the 12th, 13th and 15th character.
Yay! Free bank accounts all around!
More probably: the branch itself has a hardware VPN, so compromising the local network is still possible.
In fairness to them, they do use 2FA for anything involving moving money around.
It doesn't sound very easy to me at all. Can you explain in more detail?
e: There is a pretty good discussion of this here https://www.reddit.com/r/personalfinance/comments/2m81uj/tip...
It's also not unheard of for them to strip all non alphanumeric characters so P@ssw0rd2016! is normalized to pssw0rd2016
On the other hand, they are probably far more alert to detecting and stopping bruteforcing attempts.
It's a similar situation with certain 4-digit PINs for smartcards; that may seem trivial to bruteforce, but you only get 3-5 tries before the system considers you to be attacking it and permanently locks you out even if you try to enter the correct one afterwards.
Chase's online banking login is case insensitive ...
So is the case with Citi.