Password Managers and Banking?

Has any one here on MSE Forum any experience of Banks attitudes towards customers using Password Managers in the specific case of the customer having to make some sort of claim about fraud or loss of funds, etc?

I am looking at installing a Password Manager and as a novice in this area wondered if it could help or hinder in the above scenario. A quick search of the Techie Stuff area tells you quite a bit about Password Managers, but not much about Banks attitude to this in the event of a claim/loss. I reckon quite a few on here might have noteworthy experience or opinion. TIA.
«134

Comments

  • RG2015
    RG2015 Posts: 6,043 Forumite
    Ninth Anniversary 1,000 Posts Name Dropper Photogenic
    The banks tell you not to write down your passwords or pins or to reveal them to anyone. They could argue that entering your security data into a password manager is in breach of this condition. IT systems are always vulnerable whatever the IT companies may claim.

    Do you believe the banks would try anything to avoid paying out on a claim if they could?
  • Bobblehat
    Bobblehat Posts: 700 Forumite
    Seventh Anniversary 500 Posts I've been Money Tipped! Name Dropper
    Thanks RG2015 … this was the sort of thing I had in mind when I asked the question. 

    I wouldn't want to find out the hard way that they used PM as an excuse not to pay out!
  • mwarby
    mwarby Posts: 2,048 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    There's also the aspect of how you use the password manager, how secure is your master password, do you use two factor etc
  • Lomcevak
    Lomcevak Posts: 1,026 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    edited 7 March 2020 at 1:42PM
    I've also used one for ten years or so (1Password, in my case), and provided you're using a strong master password and two-factor authentication I cannot see how the bank could claim you had not taken reasonable care of your credentials. You could also point out that the UK National Cyber Security Centre best practice recommends organizations let users use password managers ("Help users cope with password overload: 1. Allow users to securely store their passwords, including the use of password managers.").
    However, password managers aren't a magic bullet, and lax practice could be seen as lack of reasonable care. The bank would have to prove that though.

    One option for the paranoid - which I use occasionally for critical accounts - is to store the bulk of password in a password manager, then then prefix and/or append some additional characters that are either memorized or stored elsewhere. An attacker then not only has to compromise my master password and physical two-factor token (no SMS here) but then brute-force the remainder.
    Good article here from Troy Hunt if you fancy some further reading :):smile:https://www.troyhunt.com/passwords-evolved-authentication-guidance-for-the-modern-era/




  • oli356
    oli356 Posts: 171 Forumite
    100 Posts Name Dropper
    In the unlikely circumstance that someone got your password and 2fa method. 

    Is the bank really going to ask how you remembered your password?
    If I wrote my password down  obviously I'm not going to tell the bank I wrote it down and someone got hold of it somehow. I'm going to say I had remembered it.
    Stealing a phone and finding out the 6/8? digit pin which you could see someone use in public to get access to the banking app is a more likely scenario I would think. 
  • gsmh
    gsmh Posts: 640 Forumite
    Fifth Anniversary 500 Posts Name Dropper
    edited 7 March 2020 at 3:29PM
    A password manager is of limited use for most online accounts I have used - they usually require specific letters/digits of a password and sometimes one of several saved responses to specific questions. A password manager is of no use in these circumstances. The only place a password manager might be useful if if there is an initial username and password before the above.
  • trient
    trient Posts: 175 Forumite
    Sixth Anniversary 100 Posts Name Dropper
    There is no way the banks (or any provider) can tell if a password manager has been used for signing in, vs manually typing in the credentials. 
  • alanwsg
    alanwsg Posts: 800 Forumite
    Part of the Furniture 500 Posts Name Dropper
    gsmh said:
    A password manager is of limited use for most online accounts I have used - they usually require specific letters/digits of a password and sometimes one of several saved responses to specific questions. A password manager is of no use in these circumstances. The only place a password manager might be useful if if there is an initial username and password before the above.
    The password manager I use ( https://pwsafe.org/ ) has this function.
    In fact I'd find picking something like the 5th, 16th & 22nd characters out of a password rather difficult without it.

    I have to fudge the 'answers-to-silly-questions' situations a bit by saving them as a group of items under each login, but it works well enough.
  • gsmh
    gsmh Posts: 640 Forumite
    Fifth Anniversary 500 Posts Name Dropper
    edited 7 March 2020 at 4:28PM
    alanwsg said:
    The password manager I use ... has this function.
    In fact I'd find picking something like the 5th, 16th & 22nd characters out of a password rather difficult without it.
    I have to fudge the 'answers-to-silly-questions' situations a bit by saving them as a group of items under each login, but it works well enough.
    Now that's interesting. Your bank login asks for the 5th character of your password and pwsafe supplies it? I've never heard of that! I use Bitwarden and it autofills whole passwords but there's no way it could supply a specific character.

Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 349.9K Banking & Borrowing
  • 252.6K Reduce Debt & Boost Income
  • 453K Spending & Discounts
  • 242.8K Work, Benefits & Business
  • 619.6K Mortgages, Homes & Bills
  • 176.4K Life & Family
  • 255.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.