TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Two Canadian banks say accounts compromised: CIBC 40,000 and BMO 50,000

139 点作者 t1o5将近 7 年前

12 条评论

moltar将近 7 年前
Recently tried to login into PC Financial MasterCard online account. And got “your password is too long” error. What? Right! Password length validation on the login form!<p>I called CS and explained that this is impossible as I use a password manager and it worked just not long ago. They assured me that this was always the case and that I’m an idiot for forgetting my password.<p>They sent me to password reset procedure page.<p>The password procedure emails plain text temporary password, which then let’s you pick a new password.<p>When picking a new password, I tried to enter my old password that was too long, just for the heck of it, to see if it’d go thru.<p>Lo and behold, the system answered that I “cannot reuse the same password as previous 6 passwords”.<p>That’s banking-grade security right there.
评论 #17178868 未加载
评论 #17178768 未加载
评论 #17179007 未加载
评论 #17179873 未加载
评论 #17179270 未加载
ResearchAtPlay将近 7 年前
I can confirm that Scotia Bank, another major Canadian bank, does not support 2FA. This has always bothered me and is especially concerning because Canadian bank accounts can be used to log into Canada&#x27;s immigration services (CIC). That immigration account is protected only by one more layer of self-selected security questions, after which the intruder potentially has access to a swath of personal data, including passport numbers, and a very detailed personal history section.<p>In my opinion, Canadian banks are way overdue to switch to 2FA.
评论 #17175865 未加载
评论 #17175908 未加载
评论 #17176398 未加载
评论 #17180314 未加载
评论 #17178369 未加载
评论 #17178765 未加载
评论 #17176977 未加载
ficklepickle将近 7 年前
I find CBC has a bad habit of writing corporate fluff pieces. They quote an &quot;expert&quot; from SAS making some vague assurance that their security is good. SAS is a vendor to CIBC[1], but the article fails to mention that conflict of interest.<p>[1] <a href="https:&#x2F;&#x2F;www.sas.com&#x2F;en_ca&#x2F;events&#x2F;14&#x2F;cibc-user-group&#x2F;home.html" rel="nofollow">https:&#x2F;&#x2F;www.sas.com&#x2F;en_ca&#x2F;events&#x2F;14&#x2F;cibc-user-group&#x2F;home.htm...</a>
评论 #17177324 未加载
bearcobra将近 7 年前
This doesn&#x27;t surprise me. My BMO credit card has a 6 character password limit. Not minimum, limit!
评论 #17175778 未加载
评论 #17176498 未加载
评论 #17175889 未加载
评论 #17175832 未加载
评论 #17177414 未加载
评论 #17176192 未加载
评论 #17175818 未加载
dade_将近 7 年前
HSBC Canada requires 2FA with a token or their mobile bank app. It also isn&#x27;t possible to change account contact info, setup new Payees, transfer money to another country, without generating a security code with a token PIN. The contact centre agents are unable to access your account unless you can correctly answer the security questions. This does mean an agent can lock out your account though. It is a pain, but compared with the goofy BMO 6 character passwords, or worse using CIBC at all, it was a welcome change. Legacy systems galore: Scotiabank gave me a debit card once in a branch because I got angry with them and also use mail extensively (though they have a much bigger problem right now), TD Canada Trust and US TD Bank are integrated with mail and fax, and RBC has 3 different domains (not AD) (East, Central and West) and they are completely isolated which can be a nightmare when moving across the country.
评论 #17178775 未加载
评论 #17179509 未加载
评论 #17185278 未加载
richjdsmith将近 7 年前
Lovely. One can only hope that other would-be hackers don&#x27;t start poking the rest of the Canadian Bank&#x27;s archaic systems or we&#x27;ll soon see the rest of our not-so-fantastic banks on the front page of HN.<p>For anyone not from Canada, our banks are at least a decade behind the rest of the world in terms of IT - mostly due to strong government protectionism. I was a mortgage broker before changing into IT, and up until the summer of 2015, to submit a mortgage application to Scotiabank, one of big 4, you had to fax it. My buddy who works for Scotia said it wasn&#x27;t until Q1 2016 before they were able to submit a mortgage application without a fax internally.
评论 #17179357 未加载
dflock将近 7 年前
As many people in this thread pointed out: lots&#x2F;most banks suck ta this. Tiny max length passwords, not 2fa, etc, etc...<p>Are there any Canadian banks which don&#x27;t suck at this?
评论 #17176765 未加载
评论 #17176173 未加载
评论 #17176312 未加载
mFixman将近 7 年前
I have an account in BMO that I&#x27;m in the process of closing. Besides kicking myself for opening an account in a 6-digit password site, what should I keep in mind regarding my compromised data?
flyGuyOnTheSly将近 7 年前
I have to say... I&#x27;m not at all surprised about Simplii financial&#x27;s hacking...<p>I had a PC Financial bank account... and then PC Financial decided to merge their points program with Shopper Drug Mart for some reason... and then I started getting calls from Simplii financial asking me to verify my identity and let&#x27;s setup my new online bank account...<p>&quot;What?&quot; is all I could think...<p>I had never heard of Simplii financial before... nor was I aware that PC was dissolving&#x2F;selling their banking arm...<p>I logged into the account once, transferred all of my money out of that account, and logged out forever...<p>The reason I say that I am not surprised that Simplii financial was hacked is because it is hardly even a Bank imho... it was an afterthought.
评论 #17176340 未加载
bitmapbrother将近 7 年前
The security of these Canadian banks is very weak IMO. CIBC&#x2F;Simplii, for example, does not support 2FA, has no sign in or transfer email&#x2F;SMS alerts and their maximum password length, I believe, is 12 characters.
评论 #17176370 未加载
评论 #17176634 未加载
评论 #17175946 未加载
branchless将近 7 年前
&gt; Then later Monday morning, Bank of Montreal revealed that it, too, had received a tip that &quot;fraudsters&quot; had stolen data on up to 50,000 of the bank&#x27;s customers, &quot;and a threat was made to make it public,&quot; BMO spokesperson Paul Gammal said.<p>&gt; In BMO&#x27;s case, at least, the tipsters were the hackers themselves.<p>&gt; &quot;We took steps immediately when the incident occurred and we are confident that exposures identified related to customer data have been closed off,&quot; BMO said.<p>Which &quot;incident&quot;? The theft or the data or being informed they were selling their own ass back to them?<p>The only fraudsters here are the banks, claiming they are secure.<p>Will CIBC and BMO be paying higher interest rates for the elevated risk of banking with them?
paulsutter将近 7 年前
I was visiting friends in Canada and I asked “is it true that Canadians don’t lock their doors?” And they responded “oh no, Steve right? Yeah we know a guy, he locks his door”. Always polite, trying to make me feel OK for being from a place where everyone locks their door.
评论 #17176475 未加载
评论 #17176155 未加载
评论 #17178377 未加载
评论 #17177517 未加载