Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My bank and a few other companies I deal with require some sort of pin/password in order to speak to someone over the phone. When I call, the conversation usually goes something like

    "Hello Mr 67, before we start I'll need your pin"
      "I have a pin?"
    "Yes, when you set up this account you were given a pin required for phone access"
      "Really? I have no idea what it is..."
    "That's ok. If you can just answer these other few questions.         
     What's your mother's maiden name"
       [redacted]
    "and your birthdate"
       [also redacted]
    "thankyou Mr 67, now how can I help you today? ..."


These "security" questions are usually, IMHO, the weakest link.


That's why you make stuff up when initially providing the answers to be used.


and then immediately forget them, and discover that they weren't really necessary anyway and your <service> lets you in with other questions.


My bank has a password - I never use that one anywhere else, but sometimes the bank calls me out of the blue to confirm some actions / bigger transactions and then I need it.

Turns out, when I can't remember it they tell me the first 2 letters!


They must have some advanced crypto where the customer support person can only see the first 2 letters but the rest of password remains securely hashed...


:) Even if it were securely hashed, giving out the first 2 letters reduces the range of guesswork substantially, especially when combined with wordlists. Also, the service-guys have to see my password, after all, they are immediately able to tell me whether I "guessed" the right password.

I don't believe there is any hashing going on, after all, the bank in question is ANZ, they don't even use TANs for online-banking.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: