Has HL been hacked? New passwords required.

Yesterday I received a letter from HL saying that when I next login I have to create 2 additional passwords and use those instead of the master password to login.

"Once you've set up your new details you'll no longer need your Master Password and Trading Password."



So it's safe to forget both of those passwords, at least what I read from this.



Why would this be required unless the existing DB of passwords was in jeopordy?
Goals
Save £12k in 2017 #016 (£4212.06 / £10k) (42.12%)
Save £12k in 2016 #041 (£4558.28 / £6k) (75.97%)
Save £12k in 2014 #192 (£4115.62 / £5k) (82.3%)
«13

Comments

  • lisyloo
    lisyloo Posts: 30,072 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    I!!!8217;ve not had that email.
    Don!!!8217;t click on any links in the email.
    Only go directly to hl.co.uk
  • Alexland
    Alexland Posts: 10,183 Forumite
    10,000 Posts Seventh Anniversary Photogenic Name Dropper
    We both received a letter through the post with a nice glossy leaflet - looks legitimate.

    They will only ask you to provide the new details during the normal login process in the next few weeks.

    There's also a change to linked accounts where the account owner will have to nominate if the link is 'view only' or 'can trade'.

    Alex.
  • Browntoa
    Browntoa Posts: 49,591 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    Not unusual , I've had forced password changes on other sites and requirements for additional layers of password or "two step" involving one off codes.

    Companies review security all the time , or are responding to a known spate of fraud
    Ex forum ambassador

    Long term forum member
  • Browntoa
    Browntoa Posts: 49,591 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    A quick check shows they're introducing two step password login via drop down boxes to defeat keylogger software
    Ex forum ambassador

    Long term forum member
  • TrustyOven
    TrustyOven Posts: 746 Forumite
    Seventh Anniversary 500 Posts Combo Breaker
    Browntoa wrote: »
    A quick check shows they're introducing two step password login via drop down boxes to defeat keylogger software


    Thing is, they've had drop down box passwords for the login for some time already, so i'm not sure I buy into the anti-keylogger theory. They could have turned the trading password controls into dropdown boxes too if they wanted to be anti-keylogger resistant.


    But instead, they are forcing you to generate new passwords as if the old ones are no longer secure.
    Goals
    Save £12k in 2017 #016 (£4212.06 / £10k) (42.12%)
    Save £12k in 2016 #041 (£4558.28 / £6k) (75.97%)
    Save £12k in 2014 #192 (£4115.62 / £5k) (82.3%)
  • Alexland
    Alexland Posts: 10,183 Forumite
    10,000 Posts Seventh Anniversary Photogenic Name Dropper
    If the current passwords were compromised or they were increasing the complexity rules it would be a lot easier to check the last password change date on login and enforce a change if required.

    This appears to be in support of a process change on their side to move from logon/trade passwords to an "online password" and "secure number". No idea why but it sounds a bit backwards - I prefer to have passwords to enable functions rather than access methods.

    Alex.
  • jamesd
    jamesd Posts: 26,103 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Yes, it does seem that they are reducing overall account security with this change.
  • tempus_fugit
    tempus_fugit Posts: 1,189 Forumite
    Eighth Anniversary 1,000 Posts Name Dropper Photogenic
    lisyloo wrote: »
    I!!!8217;ve not had that email.
    Don!!!8217;t click on any links in the email.
    Only go directly to hl.co.uk
    It was a letter, not an email. My wife and I both received such letters from HL as well.

    In answer to the main question, they are upgrading their security methods, so nothing to do with compromised passwords.
    Retired at age 56 after having "light bulb moment" due to reading MSE and its forums. Have been converted to the "budget to zero" concept and use YNAB for all monthly budgeting and long term goals.
  • TrustyOven
    TrustyOven Posts: 746 Forumite
    Seventh Anniversary 500 Posts Combo Breaker
    In answer to the main question, they are upgrading their security methods, so nothing to do with compromised passwords.


    But that's the simple, dismissive explanation.


    Why would they need to if their security methds were good to start with?


    Any why reduce it to a number pin which has 10 permutations per digit rather than 26 for a letter?


    And why not just apply a better password policy to existing passwords?
    Goals
    Save £12k in 2017 #016 (£4212.06 / £10k) (42.12%)
    Save £12k in 2016 #041 (£4558.28 / £6k) (75.97%)
    Save £12k in 2014 #192 (£4115.62 / £5k) (82.3%)
  • Chris_Mac
    Chris_Mac Posts: 13 Forumite
    There is far more to system security than just the part that the users see (eg. Password entry and management). This does not seem like anything sinister, it appears to be a security upgrade. Reducing the second password to numerics shouldn't be an issue since they undoubtedly limit the number of failed attempts, before locking the account.

    Regards,

    Chris
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 349.9K Banking & Borrowing
  • 252.7K Reduce Debt & Boost Income
  • 453.1K Spending & Discounts
  • 242.9K Work, Benefits & Business
  • 619.8K Mortgages, Homes & Bills
  • 176.4K Life & Family
  • 255.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.