We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Santander 123 making a hacker's life so much easier (Feb 2020)

So I went to log into my 123 account today and I'm presented with a field for ID and my 5 pin number (all 5 numbers) and I'm in!

So they have completely dropped the following checks:
1) Image and passphrase - to ensure you didn't click a bogus link
2) Online password partial entry
3) Pin - partial entry
4) Any security password when you phone them. 5 pin is enough and they are happy they are talking to the account holder.

What on earth are these guys thinking in this day and age. I have tighter security on most website accounts - well actually this forum too.
I spent a fruitless hour on the phone to them being told by them that their security is VERY robust but not telling me how (learning from Donald Trump I guess), and why they are claiming that it's robust when they've removed so many initial   checks from the login. " Oh well if we feel something isn't right we'll contact you " is honestly the best I got from them.

This to me is the last straw with Santander particularly after they reduced their interest to a mere 1% on the 123 account.
Does anyone else feel this is ridiculous or that they are happy to conduct online banking with the security AFTER the login being sufficient ?

«134

Comments

  • EssexExile
    EssexExile Posts: 6,693 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Tall, dark & handsome. Well two out of three ain't bad.
  • The drop in interest rate made my decision to move from them come May, the security change made my decision to move ASAP which I did last week to Nationwide.
  • That is to login to the account, but if you actually want to transfer money you must complete text message verification. 
  • Yes and particularly so when you compare them with someone like First Direct who require a code generator to log on and if you call them to speak to them they use voice ID to identify you
  • born_again
    born_again Posts: 25,101 Forumite
    10,000 Posts Seventh Anniversary Name Dropper
    Tildaplum said:
    Yes and particularly so when you compare them with someone like First Direct who require a code generator to log on and if you call them to speak to them they use voice ID to identify you
    You can opt out of voice id.

    While Santander have dropped some of  the sign in details required. For it to be of any use to a fraudster. They would need to steal your computer. As well as you can un-tick the remember my ID. Which means you have to enter the Security number.
    Security in many ways is how hard you make it.

    >>Image and passphrase - to ensure you didn't click a bogus link<<  If someone had access to your computer it would be a easy task to spoof the image.
    Life in the slow lane
  • penners324
    penners324 Posts: 3,720 Forumite
    Seventh Anniversary 1,000 Posts Name Dropper
    Santander using your phone as part of 2FA probably. Most banks now doing this.
  • water4444 said:
    That is to login to the account, but if you actually want to transfer money you must complete text message verification. 

    Understood but it's still a privacy issue if someone can log in. Thing should be made more difficult not easier to log in when they decide to revamp their site.
  • Interestingly, Cynergy Bank contacted me this week to say they would no longer be using SMS messages for 2FA and that I'd need to download their new authenticator app.

    Conversely, Nationwide are moving away from the card reader to using SMS messages as their 2FA.
  • Thanks for the heads up I missed this in my initial search and in fact there seem to be yet another thread.
    I've since found a url where the original login page is:

    [https]://retail.santander.co.uk/LOGSUK_NS_ENS/BtoChannelDriver.ssobto?dse_operationName=LOGON

    I stumbled on this accidentally although expect it to disappear soon -  no idea how long it will be there so for those that want to retain the original login use this till you  decide on what to do next.

    I actually forced the people on the phone to raise a complaint rather than put it down to feedback, this is because I really do want to know their reasoning by way of a direct reply.


  • Louiscar
    Louiscar Posts: 22 Forumite
    Third Anniversary 10 Posts Name Dropper
    edited 25 February 2020 at 3:56PM

    Security in many ways is how hard you make it.

    >>Image and passphrase - to ensure you didn't click a bogus link<<  If someone had access to your computer it would be a easy task to spoof the image.
    This I think is more designed for those that may respond to emails that purport to be from Santander or whatever bank. If successful they will get your ID and pin. Even though the 2FA is in place it will still be a privacy issue.
    I'm however less concerned about this personally as I never respond to such emails but given that this method is still highly active must mean that a lot of people still get caught out by it.
This discussion has been closed.
★ ★ ★ Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 355.6K Banking & Borrowing
  • 254.8K Reduce Debt & Boost Income
  • 456.1K Spending & Discounts
  • 248.2K Work, Benefits & Business
  • 605.7K Mortgages, Homes & Bills
  • 179K Life & Family
  • 263.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.