-- excerpt from A Cypherpunk's Manifesto, Eric Hughes, March 9, 1993
It's funny (not haha-funny) how political policy in 2023 is still trying to catch up to morality understood 30 years ago. I remember being annoyed at newscasters abusing the term "hackers" in the late 90s and extremely broad definitions of "hacking" being applied in court-rulings. It must still be really difficult to comprehend tech and the consequences of these kinds of policies for policy makers. Either that or policy makers really are maleficent towards life, liberty and the pursuit of happiness.
That's also why terms are being used deliberately incorrectly, to move legitimate positions nearer to criminal activity. Just ask anyone interested in hobbyist chemistry.
A better example would be encryption keys.
"They say a Secret is something you tell one other person, so I'm telling you, child".
The bank knows your password. Which means they (or more precisely their agents, employees, etc.) can lose it yet they'll probably try to blame you.
It is possible to not have this happen via what's called an Augmented PAKE - the bank wouldn't know your password, but they'd be able to check you still remembered it - however almost certainly none of the systems you use today do this.
Of course leaking the hash of my password might make it easier to crack, to some extent, but if they've done a good job then this is much better than it being something the bank can trivially lose.
Any bank that restricts which characters one can include in a password probably doesn't store a hash of it.
Even with Client side hashing, the software can still validate password requirements on the client side, you may be able to bypass those requirements by modifying the client side software.
So still no, having password requirements tells you nothing about whether the password is being stored in the clear or not. The statement that I disagreed with is still completely false.
"#" can mean phone number "+" or "&" can mean concatenate variables
It is vastly easier to screen out possible problems at the user/browser level than rewrite zillions of lines of legacy code.
Putting aside the banks who literally do store the password because they have security procedures like "Please enter the first and fifth characters of your password" even those that do store a password hash still need you to submit your password to authenticate.
So, like the lyric says, you tell the bank your password. You hope they just use it to authenticate you and immediately discard it, but if bank security lapses are anything to go by they're probably logging it "for security" and there are definitely employees able to snoop the decrypted plaintext passwords from customers on some internal teams.
That is what Augmented PAKEs fix, it's really hard to do well, and of course banks see themselves as infinitely trustworthy so why would they bother.
This mistaken sense of self-worth applies to your credit card PIN by the way also, of course banks and thus bank employees can know your PIN, which means when a purchase is "secured" by the PIN that rules out some local pickpocket having made the purchase, but as well as you it leaves open the possibility that it was a bank employee or their co-conspirator.
Normally banks can't and shouldn't know the password in most jurisdictions. It does pass to their server, but they're supposed to only store a hash of it, so not be able to know what it is.
But if anybody makes this BS argument, just ask them for the credit card number and the 3 digits on the back of the card, telling them you will post it online.
If they truly have no ethical or moral boundaries, then they are probably deviant enough that they won't be able to get into a position to set much policy, anyways, by definition of their lack of fitness to represent the majority of any population.
You go ahead and zen out and, in turn, take those things with grace by going along with it when someone raises a fuss ("oh, I am soooo humiliated! :)"). Or if you're of another archetype, you'll find witty ways to playfully snap back and turn it around on people trying to clown on you (alas, I'm not of this type/talent). Moreover, there are the countless, other not-uncommon approaches that often lead to escalation/hostility/violence.
Then it becomes a drag (and where the issue lies) when it really catches on in wildfire manner, to where it will have practically problematic effects on you personally or professionally, not unlike the lie that makes it halfway 'round the world before the truth can put its pants on.
As far as I see it, all of that is what is trying to be highlighted with the pooping witness analogy. Of course, that should probably be underscored when presenting it.
You'll probably still get a "yeah, that's fine" or "I don't care what anyone else thinks" after you elaborate. And tons of other cans of worms can reasonably be opened as topical offshoots; I'm just trying to concur that the "I don't mind" response doesn't really feel like a response.
Maybe some people even think they believe it when they say it, but I've yet to see anyone who is willing to demonstrate it when pressed, and I've even met a few people who have claimed that they have no concerns at all about their privacy, but who then ended up feeling violated when even small things they assumed were private ended up being exposed.
You should almost never be forced to nude up.