We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Platform security
Comments
-
Some of the platforms to get around non 2 FA have implemented some additional measures.
AJ Bell asks you your user id then the next page 3 letters from a 18 char (I think) password and the answer to your secret question
HL ask you for the user id and DoB then the next page is your password and three numbers out of 6 for your number password
ii user id and password
0 -
webnibbler said:
But it seems odd to me that banks are required to implement 2FA while platforms aren't.“payment service provider” means any of the following when they carry out payment services—
(a) authorised payment institutions;(b) small payment institutions;(c) registered account information service providers;(d) EEA authorised payment institutions;(e) EEA registered account information service providers;(f) electronic money institutions, including branches located in the EEA of such institutions whose head office is outside the EEA, in so far as the payment services provided by those branches are linked to the issuance of electronic money;(g) credit institutions, including branches located in the EEA;(h) the Post Office Limited;(i) the Bank of England, the European Central Bank and the national central banks of EEA States other than the United Kingdom, other than when acting in their capacity as a monetary authority or carrying out other functions of a public nature; and(j) government departments and local authorities, other than when carrying out functions of a public nature0 -
I'd guess once in an attacker would fairly easily change or add a different bank account to remove cash and then potentially sell ISA investments.
How would they easily change or add a different bank account?
I am an Independent Financial Adviser (IFA). The comments I make are just my opinion and are for discussion purposes only. They are not financial advice and you should not treat them as such. If you feel an area discussed may be relevant to you, then please seek advice from an Independent Financial Adviser local to you.3 -
csgohan4 said:you can raise the concern with your platform, but setting up the most random password you can would be pertinentI don't care about your first world problems; I have enough of my own!0
-
IvanOpinion said:csgohan4 said:you can raise the concern with your platform, but setting up the most random password you can would be pertinent
If that fails to work then it becomes a factor of length. 8 characters might take a day whereas 10 characters is over 20 years.
Anyway, extraction of a database should be incredibly unlikely, so almost any difficult to guess password should do. And of course never use the same password across companies where a weakness in one website would allow access to the other accounts.2 -
Prism said:IvanOpinion said:csgohan4 said:you can raise the concern with your platform, but setting up the most random password you can would be pertinent
If that fails to work then it becomes a factor of length. 8 characters might take a day whereas 10 characters is over 20 years.
Anyway, extraction of a database should be incredibly unlikely, so almost any difficult to guess password should do. And of course never use the same password across companies where a weakness in one website would allow access to the other accounts.
Many of our systems are being converted to 3FA (with some hopefully unnecessary talk of 4FA)I don't care about your first world problems; I have enough of my own!1 -
Deleted_User said:Some of the platforms to get around non 2 FA have implemented some additional measures.
AJ Bell asks you your user id then the next page 3 letters from a 18 char (I think) password and the answer to your secret question
HL ask you for the user id and DoB then the next page is your password and three numbers out of 6 for your number password
ii user id and password0 -
Prism said:The mostly likely modern attack comes in the form of phishing and then your password is irrelevant anyway.
My late father was nearly taken for almost £45k by fraudsters claiming to be from BT and wanting to pay him a 'refund'. Fortunately the bank blocked it before the money left the account. Took several days to convince him that it wasn't real.1 -
IvanOpinion said:csgohan4 said:you can raise the concern with your platform, but setting up the most random password you can would be pertinent0
-
tigerspill said:IvanOpinion said:csgohan4 said:you can raise the concern with your platform, but setting up the most random password you can would be pertinent0
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.7K Banking & Borrowing
- 253.4K Reduce Debt & Boost Income
- 454K Spending & Discounts
- 244.7K Work, Benefits & Business
- 600.1K Mortgages, Homes & Bills
- 177.3K Life & Family
- 258.3K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.2K Discuss & Feedback
- 37.6K Read-Only Boards