← Back to context

Comment by empyrrhicist

9 days ago

One time I had to reset my password with the power company - they had such a system, and the lady had to read me something like:

Uh4zB4DP55WD!

Apparently I was a bit salty with the system when I set it.

The fact that she shouldn't have even been able to look up the password in the first place due to hashing was lost on her.

That's pretty funny on a few levels, not in the least that they required a "secure" password like that but stored them in plain text.

  • I regularly conduct transactions at the branch of my local bank wherein they ask me for no credentials whatsoever. I also once forgot to bring my account number with me and the teller said "no worries, I'll look it up for you." Kind of horrifying.

  • My bank’s password field is case insensitive. Of course they could have lowercased it before hashing but I doubt it.

    • That's scary. I wonder if incompetence like that could lead to a lawsuit in the case of a breach.

      At this point I wouldn't be surprised if there exists a system that just asks for username with a checkbox "check here if you are the owner of this account"