https://www.bmo.com/olbb/help-centre/en/my-profile/change-pa...
https://www.bmo.com/olbb/help-centre/en/my-profile/change-pa...
- Password can't be long
- Password can't be pasted
- Password must contain symbols
- Password can't contain symbols
I even locked myself out of my credit card (AMEX) account 3 times in less than 2 days because they have multiple different password reset forms, but one of them doesn't enforce their password length limit, so I successfully set my password to a password that was too long for the web/mobile login forms.
Why is this such a common thing?
Short answer I suspect is old systems with complicated dependencies.Not only does anything digital has to be transferred over, but often customers have to be persuaded to agree to new terms, which is obviously a long, complicated process.
They also have legal legacy as the government will always grandfather old accounts when the law changes. So the banks may have special accounts that are obsolete but a few customers like the perks, that could live in an old system of their own.
Plus there are various deals they've made over time that might restrict one part of the company from doing some activity, any kind of international stuff is a total mess, it goes on.
All this means they have a ton of duplication and are constantly trying to merge their internal systems, on top of the normal awfulness of any non-tech company trying to do technology.
As a consumer, do shop around for someone who has good security practices, and point non-tech people towards them.
Theoretically, in any fraud you can get all your money back, but if the bank decides it was your fault, you have to take them to court.
In summary: there are a lot of third party products for interacting with banking data. Different versions between those products still in use. The need to enforce security based on the product/interface with the worst usability (ie: most restrictive set of functionality or most bugs to work around)
The talk specifically talks about Open Financial Exchange (OFX) as one of these legacy pieces.
Can't be pasted has changed more recently to my knowledge Can't be long is due to some OFX protocols limiting password transmission length (and sharing passwords between services in plain text!) Special characters are disallowed because some of those characters were control characters for the communication markup.
One recent example I had was with an online account that demanded a password reset. One of the requirements was "no two consecutive or three sequential characters". I'm still not quite sure what exactly it means, but it was tripped by any sequence of characters like "ab" or "21", and as a result, my generated 16-character password with no meaningful words in it was not accepted.
You know what passed the filters though? "secret_1".
https://www.theglobeandmail.com/technology/digital-culture/w...
I'm sure they're all stored in plaintext in an ancient mainframe system, but that's not the reason for the odd requirement.
Msft employees: change this!