We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Platform security
Comments
-
tigerspill said:IvanOpinion said:csgohan4 said:you can raise the concern with your platform, but setting up the most random password you can would be pertinent
I don't care about your first world problems; I have enough of my own!0 -
The form of attack will tend to be customised to the login database that is stolen. Hopefully no financial company is storing actual passwords, and hopefully they aren't storing unsalted hashes either. Most likely password guesses will be hashed and checked against the whole database. Your objective is not to be the low hanging fruit. You need to be in the lowest density password space possible, which may, counterintuitively, mean not choosing a password that is equal to the maximum length if that limit is not very high.
0 -
A woman’s HMRC account was hacked, they changed her linked bank account, altered her return so she was due a huge refund.
2FA using SMS isn’t great. Vodaphone got fined for moving someone’s number which was used for fraud, albeit they had to try 3 times before they got an obliging operative at Vodaphone.
i don’t think investing platforms would be as irresponsible, as say BA’s cavalier attitude to payment security
0 -
terry999 said:A woman’s HMRC account was hacked, they changed her linked bank account, altered her return so she was due a huge refund.
2FA using SMS isn’t great.
0 -
masonic said:The form of attack will tend to be customised to the login database that is stolen. Hopefully no financial company is storing actual passwords, and hopefully they aren't storing unsalted hashes either. Most likely password guesses will be hashed and checked against the whole database. Your objective is not to be the low hanging fruit. You need to be in the lowest density password space possible, which may, counterintuitively, mean not choosing a password that is equal to the maximum length if that limit is not very high.
0 -
Prism said:masonic said:The form of attack will tend to be customised to the login database that is stolen. Hopefully no financial company is storing actual passwords, and hopefully they aren't storing unsalted hashes either. Most likely password guesses will be hashed and checked against the whole database. Your objective is not to be the low hanging fruit. You need to be in the lowest density password space possible, which may, counterintuitively, mean not choosing a password that is equal to the maximum length if that limit is not very high.
0 -
masonic said:Prism said:masonic said:The form of attack will tend to be customised to the login database that is stolen. Hopefully no financial company is storing actual passwords, and hopefully they aren't storing unsalted hashes either. Most likely password guesses will be hashed and checked against the whole database. Your objective is not to be the low hanging fruit. You need to be in the lowest density password space possible, which may, counterintuitively, mean not choosing a password that is equal to the maximum length if that limit is not very high.0
-
Prism said:masonic said:Prism said:masonic said:The form of attack will tend to be customised to the login database that is stolen. Hopefully no financial company is storing actual passwords, and hopefully they aren't storing unsalted hashes either. Most likely password guesses will be hashed and checked against the whole database. Your objective is not to be the low hanging fruit. You need to be in the lowest density password space possible, which may, counterintuitively, mean not choosing a password that is equal to the maximum length if that limit is not very high.That is a bit concerning. I don't suppose there is much hope of them hashing the secret (which could just be a complex and random password), probably not if they are using it for other channels, such as phone support.The 3 random characters is just "security theatre", it just gives the perception of higher security. It doesn't help much against phishing, which has moved on in sophistication to scraping the actual login pages of the target sites and presenting the user with the same login challenges. It just limits the phishing site to one login session. If they can present a false login failure message the first time, they can use the second login attempt to harvest more random characters. Repeat a few times, asking for a different set of 3 characters each time to fill in the blanks... I'd imagine many users would try 2-3 times without hesitation, especially those who would tend to fall for phishing scams.2
-
One of the problems with 'secret' is that I have come across many databases were the responses are stored in plain text.
As far as phishing goes there was an advert on TV were an operator asked for characters 1,3,5, claimed that didn't go through and then asked for 2,4,6. Very very simple, no idea if that has ever been done, but demonstrated a very simple attack.
In relation to SMS, it is no longer considered a secure means of authentication - but still better than nothing.
On a similar note, have you noticed the latest version of CAPTCHA has no UI.I don't care about your first world problems; I have enough of my own!0 -
IvanOpinion said:On a similar note, have you noticed the latest version of CAPTCHA has no UI.
Despite this I still come across plenty of sites on the old versions of reCAPTCHA - the old ones are not going away yet - and I had to pass an inordinate amount of photo recognition tests to get through one website earlier today.1
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.7K Banking & Borrowing
- 253.4K Reduce Debt & Boost Income
- 454K Spending & Discounts
- 244.7K Work, Benefits & Business
- 600.1K Mortgages, Homes & Bills
- 177.3K Life & Family
- 258.3K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.2K Discuss & Feedback
- 37.6K Read-Only Boards