We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Halifax login

Hi. Just wondering if anyone else has noticed when logging into Halifax it now states you don't need a password? Seems a bit strange to lower the security and also not inform me about the change. Anyone else has this?

Comments

  • flaneurs_lobster
    flaneurs_lobster Posts: 10,448 Forumite
    10,000 Posts Seventh Anniversary Photogenic Name Dropper

    Same for Lloyds Bank, but not for Bank of Scotland for some reason.

    Here's what the explanatory text says

    Where has password gone?

    We're moving away from passwords to make signing in simpler, as we know they can be difficult to remember. From now on, you'll usually just need your username and memorable information.

    There might still be a few occasions when you'll need your password - for example, if you can't use your memorable information. If that happens, we'll carry out a verification step with a text or a call.

    Not much of an explanation is it? Our users are too incompetent to use passwords properly so we're getting rid of them? Why is "memorable information" (6-15 alphanumeric characters) better than "password" (8-32 case-sensitive alphanumerics and symbols).

    At least my Username is 30 random characters and not my email or given name.

    Sort of thing I'd expect of a social media or gaming site, not a bank.

    Dare them to go the whole hog and allow you to go password free like Microsoft do.

  • richpoortyke
    richpoortyke Posts: 169 Forumite
    Part of the Furniture 100 Posts Name Dropper Combo Breaker

    It's a poor change in my opinion. Also the site says I will no longer be able to amend the names of accounts. Which is a real shame as I like to set up pots with names so I can budget properly. No idea why that will no longer be possible

  • wmb194
    wmb194 Posts: 6,115 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
  • flaneurs_lobster
    flaneurs_lobster Posts: 10,448 Forumite
    10,000 Posts Seventh Anniversary Photogenic Name Dropper

    @masonic is right, what remains in place is still solid protection.

    I wonder if this is not tacit acknowledgement that no matter how many warnings are given and how much advice is offered about making passwords long & complicated, it doesn't really matter

    • because people will still set it to "password123", the same as all their other passwords
    • when they get 'hacked' and their account is emptied the bank will still have to reimburse them, regardless of whether their password was "qwerty" or 30 random characters.

    Unless the bank can show utter recklessness in your use of online access ("Did you write the password down and stick it to your phone?". "Er….") why bother.

    Far more money is lost by people willingly giving it to the internet because they saw a video of Nigel Farage punching Andrew Bailey on Question Time.

    A spreadsheet has been done, how much can LBG save by not having to deal with password-related queries and account lock-outs.

    Presumably they would have had to run this past their regulators to get sign-off on this?

  • masonic
    masonic Posts: 29,798 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    edited 19 April at 9:32AM

    The FCA has been pushing financial institutions towards strong customer authentication (i.e. multi-factor) and away from total reliance on passwords. This is not true only of the financial sector, reliance on passwords is generally considered problematic.

    The main reason for us choosing long complex passwords is to insure against provider breaches, where a database is stolen and the passwords cracked offline. If the banks are sufficiently confident about their security, then they may see the trade-off between password complexity and customer support to not be worth it. They would obviously be liable for any consequences linked to their loss of password data (but they are by default liable anyway). It's a necessary consequence of asking for random characters from memorable information that this information cannot be stored in the bank's database with the same level of encryption as a password that is always requested in full.

    As you say, a static password could be found out by a fraudster in a myriad of different ways, some more negligent than others, so the customer has more plausible deniability. For a one-time code sent to someone's phone and valid for only a few minutes, it is clearer that active participation by the customer is needed if they claim nobody has had access to their phone. Banks do have comeback on customers where they have ignored warnings and given one time codes to fraudsters.

    I do not know, but assume it to be the case, that the password is still needed when setting up a new payee and changing your personal details. If it is now only needed in those high risk situations, this could be considered a security enhancement by reducing the risk of exposure of this password during less sensitive use of the services.

  • wmb194
    wmb194 Posts: 6,115 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    edited 19 April at 9:47AM

    "I do not know, but assume it to be the case, that the password is still needed when setting up a new payee and changing your personal details. If it is now only needed in those high risk situations, this could be considered a security enhancement by reducing the risk of exposure of this password during less sensitive use of the services."

    Yes, it is. In the past couple of weeks when setting up new payees in the app it's begun asking me to enter my full password. In the past it was satisfied with just FaceID on my iPhone.

  • ludospot
    ludospot Posts: 1 Newbie
    First Post

    In the last few days my login has changed back the old way, Is this OK?

  • masonic
    masonic Posts: 29,798 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper

    I'm now seeing the old username + password login page, so it looks like they rolled back the change for now.

Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.6K Banking & Borrowing
  • 254.5K Reduce Debt & Boost Income
  • 455.5K Spending & Discounts
  • 247.5K Work, Benefits & Business
  • 604.3K Mortgages, Homes & Bills
  • 178.5K Life & Family
  • 261.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.