Here I came across a very funny article regarding the security implementation of HSBC Canada bank website..very funny indeed! Not only they are using easy to guess Personal Identification Question, but also they are implementing very restricted password choosing option that can be easily brute forced. Moreover they might be storing the user credentials in encrypted form--
"Since the bank is performing character matches on the password entered, there is no way that they are using a one-way hash algorithm to store the password. If they were, they would be able to match the whole thing or nothing at all. Instead, they have chosen to be able to retrieve the password and play with it. I can only hope that it isn’t stored in clear text"
More here
http://eternallyoptimistic.com/2009/08/24/so-funny-i-forgot-to-laugh/
Enjoy!
"Since the bank is performing character matches on the password entered, there is no way that they are using a one-way hash algorithm to store the password. If they were, they would be able to match the whole thing or nothing at all. Instead, they have chosen to be able to retrieve the password and play with it. I can only hope that it isn’t stored in clear text"
More here
http://eternallyoptimistic.com/2009/08/24/so-funny-i-forgot-to-laugh/
Enjoy!
Comments