Page 1 of 4 123 ... LastLast
Results 1 to 15 of 52

Thread: Westpac morons at work

  1. #1
    Join Date
    11th June 2006 - 15:52
    Bike
    Suzuki GSX1250FA, TGB 50cc moped
    Location
    Horowhenua
    Posts
    1,879

    Westpac morons at work

    Yes, its not only the Gubbermint that can come up with moronic ideas, In my humble opinion Westpac prove that private industry is at the forefront of stupidity.

    Todays internet banking logon tells me of a great new security idea. (Its not optional of course, good ideas never are.)

    I get to answer some questions "Whats your grandads name", "what was your first car", that kind of stuff.

    Then if I forget my password, all I need to do is answer the "challenge question" and I can have a new one !

    So, the russian hacker doesnt need to know my really tricky banking password anymore.

    All he needs to do is have look at my facebook page to see grandad in my friends list, and ask westpac for a new password.

    My lovely secure password and the bank site encryption now amounts to nothing, as the answers to many of the challenge questions are public domain, and even more are known to friends, family and the evil ex wife.

    Hmm. Where do we get these security geniuses from ?
    David must play fair with the other kids, even the idiots.

  2. #2
    Join Date
    25th October 2002 - 17:30
    Bike
    GSXR1000
    Location
    Christchurch
    Posts
    9,291
    I went through the same thing last week. Luckily you have more choices than your granddads name, like first street you grew up in, first pet, and lots more choices too. So unless you're stupid enough to put all your personal info on somewhere that is obviously not all that private (although you can make your facebook profile private) your squillions should be safe. Mine are.

  3. #3
    Join Date
    3rd October 2006 - 21:21
    Bike
    Breaking rocks
    Location
    in the hot sun
    Posts
    4,380
    Blog Entries
    1
    Have you seen how Kiwibanks login works? If they are trying to copy that, then that is a good thing. It's not an alternative. It's an extra and you get to set the questions. It is not a keystroke thing either so no-one can hack your computer and suss it out.
    Only a Rat can win a Rat Race!

  4. #4
    Join Date
    24th February 2010 - 21:01
    Bike
    2007 Suzuki SV1000s
    Location
    Wellington
    Posts
    728
    Quote Originally Posted by davereid View Post
    So, the russian hacker doesnt need to know my really tricky banking password anymore.

    All he needs to do is have look at my facebook page to see grandad in my friends list, and ask westpac for a new password.

    My lovely secure password and the bank site encryption now amounts to nothing, as the answers to many of the challenge questions are public domain, and even more are known to friends, family and the evil ex wife.

    Hmm. Where do we get these security geniuses from ?
    Hmm. Where do we get these security geniuses from ?..... probably Russia!

  5. #5
    Join Date
    11th June 2006 - 15:52
    Bike
    Suzuki GSX1250FA, TGB 50cc moped
    Location
    Horowhenua
    Posts
    1,879
    Quote Originally Posted by onearmedbandit View Post
    I went through the same thing last week. Luckily you have more choices than your granddads name, like first street you grew up in, first pet....

    Of course the kids who grew up in your street would know all those ones, as would your first girl friend, the ex wife and scores of people.

    While, with care you could select questions that would be hard to find, last week I was much safer as my carefully crafted, and regularly changed password was the only way in to my account.

    Now you just might be able to get in if you knew enough about me.
    David must play fair with the other kids, even the idiots.

  6. #6
    Join Date
    9th January 2005 - 22:12
    Bike
    Street Triple R
    Location
    christchurch
    Posts
    8,393
    Quote Originally Posted by davereid View Post
    Yes, its not only the Gubbermint that can come up with moronic ideas, Westpac prove that private industry is at the forefront of stupidity.

    Todays internet banking logon tells me of a great new security idea. (Its not optional of course, good ideas never are.)

    I get to answer some questions "Whats your grandads name", "what was your first car", that kind of stuff.

    Then if I forget my password, all I need to do is answer the "challenge question" and I can have a new one !

    So, the russian hacker doesnt need to know my really tricky banking password anymore.

    All he needs to do is have look at my facebook page to see grandad in my friends list, and ask westpac for a new password.

    My lovely secure password and the bank site encryption now amounts to nothing, as the answers to many of the challenge questions are public domain, and even more are known to friends, family and the evil ex wife.

    Hmm. Where do we get these security geniuses from ?
    Westpac are the most useless when it comes to this stuff. all the other bands have extra features which provide additional but by no means foolproof security
    I thought elections were decided by angry posts on social media. - F5 Dave

  7. #7
    Join Date
    17th February 2005 - 11:36
    Bike
    Bikes!
    Location
    Christchurch
    Posts
    9,649
    Only dumb faggots who don't care about their privacy would use facebook anyway.

    And FFS use your brain and put different anwers to the questions you muppet

  8. #8
    Join Date
    11th June 2006 - 15:52
    Bike
    Suzuki GSX1250FA, TGB 50cc moped
    Location
    Horowhenua
    Posts
    1,879
    Quote Originally Posted by imdying View Post
    Only dumb faggots who don't care about their privacy would use facebook anyway.

    And FFS use your brain and put different anwers to the questions you muppet
    The issue is not what you can do to provide yourself with security in spite of Westpac stupidity

    (You could as you point out use a pass-phrase unrelated to the question as the answer.)

    What erks me, is that this compulsory weakening of my security is foisted on me as a security enhancement !

    And it also erks me that idiots cant see that, but its very easy for me to ignore idiots, much harder for me to do without internet banking.
    David must play fair with the other kids, even the idiots.

  9. #9
    Join Date
    17th February 2005 - 11:36
    Bike
    Bikes!
    Location
    Christchurch
    Posts
    9,649
    Quote Originally Posted by davereid View Post
    What erks me, is that this compulsory weakening of my security is foisted on me as a security enhancement !
    It's only as weak as you make it.
    Quote Originally Posted by davereid View Post
    And it also erks me that idiots cant see that, but its very easy for me to ignore idiots, much harder for me to do without internet banking.
    If you think their security is inadequate, change banks... surely that is what any prudent person would do? Or is that in the too hard basket?

  10. #10
    Join Date
    25th October 2002 - 17:30
    Bike
    GSXR1000
    Location
    Christchurch
    Posts
    9,291
    Quote Originally Posted by davereid View Post
    Of course the kids who grew up in your street would know all those ones, as would your first girl friend, the ex wife and scores of people.

    While, with care you could select questions that would be hard to find, last week I was much safer as my carefully crafted, and regularly changed password was the only way in to my account.

    Now you just might be able to get in if you knew enough about me.
    And if they know your customer id. Now if they've made it that far, you have been too sloppy.

  11. #11
    Join Date
    26th February 2009 - 06:43
    Bike
    -
    Location
    Auckland
    Posts
    345
    The password for ASB internet banking is case insensitive so there goes your increased complexity with upper & lowercase letters. P7iUYt8R = p7iuyt8r as far as they're concerned. (No, that's not my password)

    DM
    Watch out for tow ropes and quickly braking cars

  12. #12
    Join Date
    11th June 2006 - 15:52
    Bike
    Suzuki GSX1250FA, TGB 50cc moped
    Location
    Horowhenua
    Posts
    1,879
    Quote Originally Posted by onearmedbandit View Post
    And if they know your customer id. Now if they've made it that far, you have been too sloppy.
    So IF they know my customer ID, I accept that I have been careless.

    But my password is a tough nut to crack, and it was the only key.

    Now my password is not the only key.

    Westpac has added a whole list of new keys to my account. Some of which may be easier to guess than my password.

    How exactly does this help me be more secure...?

    Scenario.. someone steals my wallet, and therefore have my drivers licence, DOB, address, and Westpac account number.

    At the moment they cannot use that to guess my password. But the security questions are known to all westpac customers, and all hackers.

    An hours googling could find answers to many of the questions. The best bit is, that if they guess my challenge questions, then they already know how to answer the challenge question they need to answer to transfet BOTH my dollars to russia.
    David must play fair with the other kids, even the idiots.

  13. #13
    Join Date
    25th October 2002 - 17:30
    Bike
    GSXR1000
    Location
    Christchurch
    Posts
    9,291
    Quote Originally Posted by davereid View Post
    So IF they know my customer ID, I accept that I have been careless.

    But my password is a tough nut to crack, and it was the only key.

    Now my password is not the only key.

    Westpac has added a whole list of new keys to my account. Some of which may be easier to guess than my password.

    How exactly does this help me be more secure...?

    Scenario.. someone steals my wallet, and therefore have my drivers licence, DOB, address, and Westpac account number.

    At the moment they cannot use that to guess my password. But the security questions are known to all westpac customers, and all hackers.

    An hours googling could find answers to many of the questions. The best bit is, that if they guess my challenge questions, then they already know how to answer the challenge question they need to answer to transfet BOTH my dollars to russia.
    You're account number is different to your user id, that should never be written down. You can also modify your user id to something unique.

    I do understand what you are saying. However I'd like to know Westpacs reasoning behind it. (I'm assuming there is a legitimate reason for the change)

  14. #14
    Join Date
    13th December 2008 - 18:22
    Bike
    Your mom
    Location
    Christchurch
    Posts
    3,901
    BNZ customers have this plastic card with different numbers on it, and you have to look at the card and enter numbers off the card in order to access the account. It seems like a good idea, as long as the thief/fraudster doesn't get hold of that card.

  15. #15
    Join Date
    17th February 2005 - 11:36
    Bike
    Bikes!
    Location
    Christchurch
    Posts
    9,649
    Quote Originally Posted by davereid View Post
    An hours googling could find answers to many of the questions. The best bit is, that if they guess my challenge questions, then they already know how to answer the challenge question they need to answer to transfet BOTH my dollars to russia.
    Which the bank will reimburse you for. Just change all of your challenge question answers to the same as your password if you think your password is bulletproof. Or gibberish... you can still ring the bank to have your password reset if required, but that'll never happen because you change them regularly enough.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •