beldmit: (Программизм)
[personal profile] beldmit
I have an account with one of HSBC's banks and in my case their password
use is pretty impressive. (I don't know how it varies around the world
with different instances of HSBC.)

1. They chose the password, not me. (So not duplicated elsewhere, at
least not initially.) Short, alpha-numeric.


2. When I login, they want my account number. Their Javascript doesn't
allow pasting, I used to use X11 middle-click pasting but one day they
decided I was a specific piece of Windows malware and locked me out
until I had my computer professionally cleaned. I managed to talk them
out of that for my Linux machine--but I don't middle click any more. (I
actually ended up talking to someone pretty real.) They are watching
their attacks, maintaining a security model on each customer.

4. They want the answer to a security question (effectively a password I
have chosen).

5. They want their password--but only a few positions, they show a form,
graying out boxes for positions they are not interested in.

In their model they are keeping track of when they have used which
character positions (when a keyboard sniffer might have discovered a
position). They seem to settle on the same character positions for a
long time, until something interesting happens (such as logging in with
a smart phone app), then they shift them. I bet their HTML doesn't
obviously reveal which positions they are requesting, to make the
sniffing harder.

They are being pretty clever to make up for terribly endpoint security.


Первоисточник

Date: 2013-12-24 02:35 pm (UTC)
From: [identity profile] maksa.livejournal.com
Думаю, это дело рук какого-то одного фаната, которому почему-то разрешили развернуться по полной.
From: [identity profile] livejournal.livejournal.com
Пользователь [livejournal.com profile] wizzard0 сослался на вашу запись в записи «Банковская безопасность/endpoint security для параноиков (http://wizzard0.livejournal.com/376740.html)» в контексте: [...] Оригинал взят у в Банковская безопасность для параноиков [...]

Date: 2013-12-25 10:43 pm (UTC)
From: [identity profile] sagarasousuke.livejournal.com
один прибалтийский центр аэронавигационной информации (AIS) тоже... присылает матрицу "одноразовых" паролей и спрашивает вразнобой.

зачем и от кого берегутся - мне как конечному пользователю непонятно :)

Profile

beldmit: (Default)
Dmitry Belyavskiy

December 2025

S M T W T F S
 123456
78910111213
14151617181920
2122 2324252627
28 29 3031   

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Feb. 12th, 2026 08:54 pm
Powered by Dreamwidth Studios