This doesn't make sense to me. Any "legacy" systems involved surely pre-date online account access by consumers. They would not have ANY password field or even any notion of a "user" in the sense of someone who is able to access a specific account.
This would have all been built as a web application talking to the backend through a CICS gateway of some sort. The web app would be responsible for authenticating the user, not the legacy mainframe system.
Comments
This doesn't make sense to me. Any "legacy" systems involved surely pre-date online account access by consumers. They would not have ANY password field or even any notion of a "user" in the sense of someone who is able to access a specific account.
This would have all been built as a web application talking to the backend through a CICS gateway of some sort. The web app would be responsible for authenticating the user, not the legacy mainframe system.
They probably keep the password in an 8-char record that used to store something else.