Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They're pretty terrible when they do.

For the longest time the max password size was 8 characters and the csr knew what your password was.

Heck I've had Chase security tell me they'd call me back.. dude that's exactly how people get compromised.



A friensd bank, hopefully not the one i use, only allow a password off 6 digits. Yes You read it right, 6 fucking digits to login, i hace him the asvice to run away from that shitty bank


Did this bank start out as a "telephone bank"? One of the largest German consumer banks still does this because they were the first "direct bank" without locations and typing in digits on the telephone pad was the most secure way of authenticating without telling the "bank teller" your password. So it was actually a good security measure but it is apparently too complicated to update their backend to modern standards.

They do require 2FA, though.


DiBa?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: