If that wasn't bad enough, look at how services like Mint have to interface with these institutions? When will something like OAuth come into play at banks?
I'd love to charter a bank on the premise of superior online service.
If that wasn't bad enough, look at how services like Mint have to interface with these institutions? When will something like OAuth come into play at banks?
I'd love to charter a bank on the premise of superior online service.
It's the only explanation I can come up with.
I can't speak for most financial systems (I only am familiar with one, but it's a big one), but I know plain text passwords happen. Lets call the system IET.
IET doesn't encrypt the passwords used for internet banking. To obscure the passwords, they're stored in the DB using EBCDIC. No joke.
Sure, in theory, encryption of data at rest doesn't matter if the system is secure; however, with a security posture like this, the data is bound to leak.
In this case, I found out about the unencrypted passwords because they were in the files going to the "print & statement" vendor: there is a default letter in the system that says "Hey your password changed to foo99!". Despite suppressing this letter, the data was still transmitted to the vendor: it is simply ignored.