this post was submitted on 04 Apr 2024
1019 points (98.8% liked)

linuxmemes

21448 readers
1091 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack members of the community for any reason.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • These rules are somewhat loosened when the subject is a public figure. Still, do not attack their person or incite harrassment.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn. Even if you watch it on a Linux machine.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, and wants to interject for a moment. You can stop now.
  •  

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't fork-bomb your computer.

    founded 1 year ago
    MODERATORS
     
    you are viewing a single comment's thread
    view the rest of the comments
    [–] [email protected] 58 points 7 months ago (2 children)

    Because as per usual they don't understand security. I have started choosing my bank based on software they have. If software looks competent, that's my most significant influence.

    They think rooted device = insecure device, but at the same time PC is even less secure and yet all the business users use them and more to the point have passwords written on a sticky note glued to the screen. My old bank at one point "upgraded" their software system and then started asking me for weird characters in password and then asked for maximum length which was the final sin I allowed them to commit. Left them that week.

    [–] [email protected] 30 points 7 months ago (2 children)

    My bank keeps their app up to date with all the latest anti-root stuff but allows passwords made of 5 digits. ¯\_(ツ)_/¯

    [–] [email protected] 7 points 7 months ago (2 children)

    Unless they've changed it very recently, Paypal still limits your password to 20 characters

    [–] [email protected] 10 points 7 months ago (1 children)

    Unless they’ve changed it very recently, Wells Fargo’s passwords are case insensitive

    [–] [email protected] 6 points 7 months ago (1 children)

    Air Canada's online account system required a 6 character password, which was secretly converted via T9 to 6 numbers on the back end, meaning "aaaaaa" and "bbbbbb" were effectively the same password, and this was only fixed in 2018

    [–] [email protected] 2 points 7 months ago (1 children)

    That sounds like someone who topped out with highschool level programming tried to implement a hash algorithm.

    [–] [email protected] 4 points 7 months ago

    My personal theory is that it's a remnant of an old system that was only accessible by phone (hence the 6 digit pin), and they simply grafted an online component on top of it

    [–] [email protected] 5 points 7 months ago (1 children)

    Any service that limits maximum length of the password means they are not hashing them. Which is a scary proposition, especially for such a huge service.

    [–] [email protected] 3 points 7 months ago (1 children)

    That's normally my assumption too but surely PayPal has proper security, right? Right??

    [–] [email protected] 2 points 7 months ago

    It's possible that limit is either gone or vestige from a bygone age and they are hashing passwords properly now. Either way they do seem like they take security seriously.

    [–] [email protected] 4 points 7 months ago

    Ah, that's the "your problem" approach to security.

    [–] [email protected] 17 points 7 months ago (1 children)

    You're better off with random different passwords for each service written on a sticky note than using the same password/email combofor multiple accounts.

    [–] [email protected] 8 points 7 months ago (2 children)

    I mean, you're comparing very different scenarios.

    If one account gets broken into and their password hashing was crap, the attacker can try the email/password combo with other services and can stumble onto another one you use.

    If someone has access to your sticky note they have all your accounts.

    I don't think I'd call either of them better.

    Of course, all this assumes no second auth factor.

    [–] [email protected] 4 points 7 months ago (1 children)

    If someone has access to your sticky note they're already in your house, and that's a bigger issue IMO... even from an itsec perspective, once the attacker has physical access to guarantee safety is difficult.

    But seriously, there's a guy in your house.

    [–] [email protected] 3 points 7 months ago* (last edited 7 months ago) (1 children)

    But seriously, there's a guy in your house.

    My house is not a prison... yes, other people come over. There's the occasional party, handymen doing work, neighbors, parents of kids from school, kids sleeping over, and so on. It doesn't have to be the ninjas breaking in.

    If you don't casually keep wads of cash in the open around the house you probably shouldn't have logins on a post-it either. But to be fair the kind of person that does the latter does the former too.

    [–] [email protected] 1 points 7 months ago

    If I know they are there then I either supervise visitors or trust them to not rummage/take my stuff. If that is your issue then keep your postit in a drawer; most people don't keep their yubikeys in a securely bolted safe either.

    [–] [email protected] 1 points 7 months ago

    Just shift the password descriptions a few spots compared to the passwords, then you'll get email about failed logins as a canary.