For any customers that do use said bank, take this as an indicator of their own security practices and consider if you still trust them with your money, data and PII.
I wonder how they share credentials without a PAM or similar. All service accounts are using 'S3cur3P@$$w0rdzSuck'... Or more probably just a 'passwordz'?
I use said bank and they are generally pretty good. Also note they even said in the tweet that they acknowledge the role of password managers so I think you may have read a bit too much into the tweet. Almost every time I log on to their online banking site, I get a page detailing the latest scams and what to look out for.
I also agree with their statement for the most part. The general public, at least here in SA, aren't too discerning when it comes to tech matters who will probably download any random app from the play store. If you don't trust pretty much anyone with your credentials, why trust a probably unknown 3rd party with them.
I think the best idea in this case is to choose a strong password, try and remember it or write it down and store it in a safe.
I've been meaning to leave them since they implemented this policy last year. I uninstalled their app and have been getting by using the _Don't Fuck with Paste_ extension [0].
But I do totally agree with you that if they're blocking password manager functionality then it follows that there are probably many more security practices they're similarly getting completely wrong. It's especially concerning when you think of how basic an error this is to be making.
I don't know how security policies are written at companies their size, but there are so many resources on the benefits of password managers it's hard to believe no one could google "should you disable copy pasting passwords" and then read any link from the last 10 years which will unambiguously say: No!
Another weird security issue I noticed with them last week, is that they seem to have their email template sharepoint public [1]. This could be commonplace, since you can't edit anything, but still seems weird that you would let just anyone traverse your directories.
Comments
For any customers that do use said bank, take this as an indicator of their own security practices and consider if you still trust them with your money, data and PII.
I wonder how they share credentials without a PAM or similar. All service accounts are using 'S3cur3P@$$w0rdzSuck'... Or more probably just a 'passwordz'?
What a shocking state of affairs.
I use said bank and they are generally pretty good. Also note they even said in the tweet that they acknowledge the role of password managers so I think you may have read a bit too much into the tweet. Almost every time I log on to their online banking site, I get a page detailing the latest scams and what to look out for.
I also agree with their statement for the most part. The general public, at least here in SA, aren't too discerning when it comes to tech matters who will probably download any random app from the play store. If you don't trust pretty much anyone with your credentials, why trust a probably unknown 3rd party with them.
I think the best idea in this case is to choose a strong password, try and remember it or write it down and store it in a safe.
I've been meaning to leave them since they implemented this policy last year. I uninstalled their app and have been getting by using the _Don't Fuck with Paste_ extension [0].
But I do totally agree with you that if they're blocking password manager functionality then it follows that there are probably many more security practices they're similarly getting completely wrong. It's especially concerning when you think of how basic an error this is to be making.
I don't know how security policies are written at companies their size, but there are so many resources on the benefits of password managers it's hard to believe no one could google "should you disable copy pasting passwords" and then read any link from the last 10 years which will unambiguously say: No!
Another weird security issue I noticed with them last week, is that they seem to have their email template sharepoint public [1]. This could be commonplace, since you can't edit anything, but still seems weird that you would let just anyone traverse your directories.
[0] https://chrome.google.com/webstore/detail/dont-fuck-with-pas... https://addons.mozilla.org/en-US/firefox/addon/don-t-fuck-wi... [1] https://www.mailers.fnbweb.co.za/Campaigns/Forms/AllItems.as...