Robinhood worked well for bootstrapping my portfolio with free trades, but after a certain point it got big enough for me to worry about other factors like this.
Robinhood worked well for bootstrapping my portfolio with free trades, but after a certain point it got big enough for me to worry about other factors like this.
Example: I accidentally deposited a check into my IRA once. I called and explained I wasn't sure what to do because 1) the check was post-tax money and 2) if I tried to fix it myself, would it count as an early withdrawal?.
The guy picked up almost immediately, said yep lemme transfer you, the <something> department has a button for that. I got transferred, still to a native english speaker, who sorted me out. A couple days later it was all fixed in my account. 10/10.
I do all my banking with them and if they offered a 2% cashback credit card, I'd move that to them too.
Speaking of which, Citi (I have the doublecash) has been dreadful - my card # got stolen once, and they sent the new credit cards to my old address (that I still - for a bit longer - owned, thankfully) even after I specifically stressed, and confirmed multiple times, that I was 300 miles away from the address and if they sent them there, they'd sit in my porch for 1-2 weeks before I could get to them, and I would also not have a credit card to use.
They reassure me, even getting a bit snippy at the end of the call, that they're sending them to the address I gave them (my parents' house) on the call. And since I'm such an important customer, they're overnighting the cards.
Sure enough, the next day, I check my security camera and see a dang cardboard envelope that says CITICARDS all over it sitting on my old porch 300 miles away.
So I call them up, explain that they did exactly what I asked them not to do, and if they could cancel those cards and try sending them again, because I don't have a credit card right now, and I'm trying to furnish and move into a new house and need to put about $10k of appliances purchases through the cards ASAP. They explain that, sorry, they need to wait a week or two (I was incensed and don't remember clearly at this point) before they can do anything.
Luckily a week later when I rolled up to finish cleaning the old house, the cards were still there, albeit a bit damp.
In the meantime I'd applied for a Blue Cash Preferred (which gets 6% cashback on instacart!) and they had it to me overnight and dropped it on the doorstep of my new house which was a new construction and not even in some systems yet as a valid address. Their support as been good so far, too, though I haven't had to call them but once so far.
(Thanks for coming to my TED talk.)
Or is it not real 2FA somehow?
The email one has different problems (what if my email's hacked too?)
https://client.schwab.com/clientapps/access/securityCenter#/...
And to enter it, you ... append it to your password?
I'm personally going to hold off on giving them the greenlight here.
>And to enter it, you ... append it to your password?
Are you implying this is wrong somehow? It's a fairly common way to do 2FA and there's nothing wrong with it. On the backend, all it's doing is taking the input, substringing the final 6 characters and inputting that as the code, and then uses the remaining characters as the password input. It's essentially just a shortcut that allows you to log in with one click rather than having to enter your password, click submit, enter a code, then click submit again.
Per the FAQ, if you for some reason don't want to append it to your password, it'll send you to a normal "Enter your 2FA code" form like you're probably used to.
The main issue for me is that the 2FA is locked to using the Symantec VIP 2FA app, which is disappointing from a usability standpoint.
But here's where it can go wrong, using ETrade as a specific example. ETrade appends the 2FA token to your password, but also enforces a password character limit. Yep, that means turning on 2FA reduces your password character limit. From what I hear, it has some surprising behavior if your password is already at the character limit and you turn on 2FA.
(Aside: ETrade has some very sketchy security practices, like apparently letting you use the 2FA token on its own to reset your password (according to a coworker), but that's another discussion.)
FWIW I think 2) is the bigger sin here.
I'm not sure if they still do this.
http://mattstockton.com/2013/03/20/my-bank-password-is-sort-...
I think I recall Vanguard having had something similar but I can't find it in searching, so perhaps not.
I basically assume any financial institution that provides support for the old "telephone banking" methods via DTMF tones either stores your password in plaintext or a hashed version that reduces entropy. I'm honestly surprised hackers haven't gotten sophisticated enough to bruteforce these reduced entropy login passwords using a Twilio account.
[0] https://www.fidelity.com/customer-service/phone-numbers/over...
It still will allow you to avoid phishing if you never use the sms fallback, but it does make you vulnerable to sim attacks of the variety "convince phone store rep to replace 'your' lost sim card"
Any kind of otp/totp leaves you with too much risk
Schwab has a US based super super helpful call center. They will talk to visa on your behalf and fix any problems immediately. They will go out of there way to be very nice and helpful. they've waived wire fees for me when they had very little reason to. So amazing.
You can't even get a human on the phone at TCF and they even recently got rid of local branch phone numbers you can't find it - which is insane.
[0]Transfers kept failing for no clear reason. [1]My account got into some sort of state where if I tried to login it said my account didn't exist, but when I tried to create a new one it said I already had an account.
You are right that Schwab makes a pretty good profit from it. The way they do that is by lending "your" money to their margin customers and charging those people 7% or more while paying you pennies.
In a "margin" brokerage account, "your" money is merely a debt obligation of Schwab.
TD Ameritrade (and now I think Schwab) will sweep cash from your brokerage account into a real, genuine, bank account. But the interest rate is still almost nothing.
https://www.sfgate.com/business/article/The-genesis-of-disco...
Unfortunately, I have to disagree. While I never had any major problems with them, my company's 401k accounts used to be with them. At the time (this was about 5 years ago) you couldn't have a password longer than 8 characters and they didn't support 2 factor authentication. They had it, just not for your account. It was quite frustrating. Maybe they've finally wised up? But even so, that's hardly keeping up well with tech.
It was even worse, if such a thing is possible. Passwords were case insensitive.
https://1password.community/discussion/60363/psa-schwab-now-...
There was an HN discussion about this, but the original article is now lost to the mists of time.