Two Canadian banks say accounts compromised: CIBC 40,000 and BMO 50,000
cbc.ca
cbc.ca
I called CS and explained that this is impossible as I use a password manager and it worked just not long ago. They assured me that this was always the case and that I’m an idiot for forgetting my password.
They sent me to password reset procedure page.
The password procedure emails plain text temporary password, which then let’s you pick a new password.
When picking a new password, I tried to enter my old password that was too long, just for the heck of it, to see if it’d go thru.
Lo and behold, the system answered that I “cannot reuse the same password as previous 6 passwords”.
That’s banking-grade security right there.
Do they throw up an error? No, they silently truncate it.
The cherry on top is that it’s also case insensitive.
I stick with them because they’re good otherwise and they make it clear that they take responsibility for any losses due to this nonsense. But holy crap, “bank grade security” is definitely not a positive thing in my eyes.
Def not the case anymore.
There is no cloud, just other people's computers.
In my opinion, Canadian banks are way overdue to switch to 2FA.
Ironically i signed up with one of the local credit unions in Toronto to take advantage of a high interest savings account for a future tax debt of which I am sitting on the cash for, and found they supported SMS 2FA, and texts when anyone (even me) logged into the account. I wish TD supported this, but then again, as long as their money is backed by the government i don't really care all that much.
1) Many people have had their Gmail account for a long time, starting before SMS-based 2FA was widely known as a security disaster (this is in fact still not widely-known)
2) Google still actively encourages users to add a recovery phone number
3) Users could have added a phone number years ago then forgotten (this was the case with myself)
4) Users often have many websites using their Gmail account for password-reset workflows (this is definitely the case with myself)
All of these combine to make Gmail the ideal hacker entrypoint. See this hack: https://www.reddit.com/r/ethtrader/comments/8klw4f/someone_j...
i would consider the average person to be pretty bad at handling otp backups. how else would you do recovery?
All these things are beyond what the average person wants to worry about, as you say, but HN readers will find it simple. Personally I'm hoping U2F (Yubikeys) are the future, since your average person certainly understands the concept of a key.
I would much prefer to see a second factor like TOTP, U2F, etc as the problems with SMS based second factor are well documented, but I'll take what I can get.
For anyone who wants to set it up you can find it by...
1) Logging into Easy Web
2) Click your name in the top right
3) "Password and security"
I'm not sure I understand why you believe SMS codes as a second factor compromise the security of the password authentication.
Or, sometimes, you don't even need login access; one notable attack has been to the credit-reporting systems, where to unfreeze your credit report (and thereby apply for new credit lines) the reporting agencies require your name, birthdate, SSN, and SMS verification. But if the attacker already has name, birthdate, and SSN... well, that's all they need to get the cellular ISP to redirect the SMS verification, as well.
So I really don't see how this makes security worse.
That’s why proper banks should use 2FA mechanisms that will ask the user to confirm the transaction on a second device (e.g. photoTAN or similar).
Of course, this won’t help against attacks if both devices are compromised or you are using the second factor device to access the system, but it’s still better than TOTP.
And, of course, TOTP is still way better than SMS 2FA or no 2FA.
Unless of course your bank does some proper, additional verification for large volume transfers.
Got a name? And do you recommend them? Long-time RBC customer, which means they treat me terribly. Mortgage is coming up for renewal soon enough.
Accounts can also be used to log in to the CRA website.
"we're not responsible if we get hacked and lose all of your CRA related data to some random hacker... that's your fault"
SMS is not secure for this purpose since there are many attacks which allow you to sniff SMS messages.
I've looked around an account I'm a representative on, and other than passport numbers, not much sensitive personal data.
CIC is still a lot of pen and paper these days, but perhaps it depends on one's immigration pathway...
The bank's information can be used to log into CRA however...
It boggles my mind that institutions with such financial power, fail to employ these practices.
It's clearly not a question of cost..
[1] https://www.sas.com/en_ca/events/14/cibc-user-group/home.htm...
The UK essentially taxes households with a TV in order to prop up the BBC. When I was growing up in the UK in the early 2000s we didn't watch broadcast TV but we had a TV. A couple of times a govt license officer came over and demanded to be let in the house to inspect our TVs. I loved how my dad stood up to him and told him to basically fuck off.
The whole TV licensing thing is basically based on the assumption that most people want to follow the law most of the time, which it turns out is a true assumption.
I absolutely understand this, the problem at the time the officers were notorious for presenting themselves as if they had a right to enter your house. They would be particularly pushy and work on the assumption that you were going to let them in. Myself, my father, and a friend all experienced this; guy turns up, says he needs to come in to inspect the TV, when you refuse to let him in says he will come back with some kind of legal paperwork to allow him to enter, returns another day hoping someone else opens the door.
> The whole TV licensing thing is basically based on the assumption that most people want to follow the law most of the time
This is BS, they had infamous adverts on TV saying they would 'catch you out', suspecting the public were stealing the airwaves.
https://www.youtube.com/watch?v=EnnaPfAEISo
https://www.youtube.com/watch?v=1Q9CsRRhWQI
https://www.youtube.com/watch?v=8NmdUcmLFkw
^ Three decades of threatening the public. You tell me that those ads don't make it look as if the officers are gov't employees and have a legal right to inspect your home. In fact, from those ads it makes it look as if they can tell from outside your home that you have broken the law, I am pretty skeptical that any of that would stand up in court as conclusive evidence.
Fact is you can legitimately own a TV and not want to watch the BBC, but the BBC insists that owning a TV is essentially the same as wanting to watch BBCTV.
</rant>
But then, all of our media outlets are like that so maybe it's just a Canadian thing. Take this as an example:
http://toronto.citynews.ca/2018/05/28/fake-passports-convict...
You can get a passport by simply skipping a line and heading straight to a known to be compromised employee, no simple secondary checks in place. An obvious gaping hole, and not a single newspaper has the competence (or bravery) to notice.
"Tangerine, much like BMO, also has a six character limit – numbers only, no letters and no special symbols allowed."
https://www.theglobeandmail.com/technology/digital-culture/w...
Changing a legacy mainframe COBOL system shouldn't be scary. Provided you have qualified staff and the right tools (such as COBOL static analysis tools), it is not inherently more risky than changing a Java or .Net app.
So ING sold it off to The Bank of Nova Scotia (BNS).
Canada's bank-friendly anti-consumer policy meant that ING Direct had some value, and BNS coughed up the most cash.
They were only allowed to use the orange ING branding for a few years, so they changed it to something that was borderline familiar: an orange fruit.
BNS probably had to, or chose to, switch ING clients over from the Dutch back-end to their Canadian one.
When showing you the picture and phrase: >Important: If you don't recognize or see your picture and phrase, don't enter your PIN. First check that you entered the correct information. If you're still unsure, call 1-888-SAFE(7233)-304.
Anyone care to guess my username, and steal my picture and phrase?
1 character passwords allowed?
The password size is fixed at 6 integers. No more, no less.
ref: https://www.ibm.com/support/knowledgecenter/en/SSLTBW_2.1.0/...
And I quote:
If you are RACF-defined, you must enter the password defined in the RACF® data set as the value for password. The new password specifies the password that is to replace the current password. new_password must be separated from password by a slash(/) and, optionally, one or more standard delimiters (tab, blank, or comma). new_password is 1 to 8 alphanumeric characters long. This operand is ignored for non-RACF defined users. (Printing is suppressed for some types of terminals when you respond to a prompt for a password.) With z/OS® V1R7 or later, the password and new_password can be in mixed case, if your installation has enabled RACF mixed case password support.
For anyone not from Canada, our banks are at least a decade behind the rest of the world in terms of IT - mostly due to strong government protectionism. I was a mortgage broker before changing into IT, and up until the summer of 2015, to submit a mortgage application to Scotiabank, one of big 4, you had to fax it. My buddy who works for Scotia said it wasn't until Q1 2016 before they were able to submit a mortgage application without a fax internally.
I would not agree with your assertion. I work at the bank with the "Green Sofa " and I can assure you we are very competitive with the US banks as far as technology goes.
Are there any Canadian banks which don't suck at this?
RBC supports finger print auth with their app, and forced security questions.
I had a PC Financial bank account... and then PC Financial decided to merge their points program with Shopper Drug Mart for some reason... and then I started getting calls from Simplii financial asking me to verify my identity and let's setup my new online bank account...
"What?" is all I could think...
I had never heard of Simplii financial before... nor was I aware that PC was dissolving/selling their banking arm...
I logged into the account once, transferred all of my money out of that account, and logged out forever...
The reason I say that I am not surprised that Simplii financial was hacked is because it is hardly even a Bank imho... it was an afterthought.
Simplii isn't "hardly a bank". It's a bank powered by the same software as CIBC. It's like the Koodo of Telus.
Credit card apps will ask: "Enter your occupation, be as descriptive as possible", and I'll hit the limit...
> In BMO's case, at least, the tipsters were the hackers themselves.
> "We took steps immediately when the incident occurred and we are confident that exposures identified related to customer data have been closed off," BMO said.
Which "incident"? The theft or the data or being informed they were selling their own ass back to them?
The only fraudsters here are the banks, claiming they are secure.
Will CIBC and BMO be paying higher interest rates for the elevated risk of banking with them?
I pay for home insurance for a reason.
I don't think people in the US lock their doors when they're home during the day.
I'm Canadian. I don't lock my door when I'm at home. I always assumed this question implied "when not at home", and I always answered that Canadians do lock their doors.