Hacker News new | past | comments | ask | show | jobs | submit login

What does the password give access to? Full online banking (e.g. being able to do transactions?). Does login not require any further authentication beyond the password?

If the authentication still requires using some kind of good 2FA then it's less serious to have the password in plaintext. Still bad of course.

If this is for some other service that doesn't let you do any transactions then it's not as serious either (still bad and embarrassing, but not that serious)

Even with properly hashed passwords etc I'd be worried if my bank allowed login with only a username/password and no further security. I didn't think even that was a thing in 2020.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: