Silicon Shecky

Infosec Practitioner

  • About
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Links
    • Infosec
      • Burbsec
      • Infosec Exchange Mastodon
      • Hacks4Pancakes Blog
      • Krebs On Security
      • Bleeping Computer
  • Archives

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

[footer_backtotop]

Copyright © 2025 ·Sixteen Nine Pro Theme · Genesis Framework by StudioPress · WordPress

The one about banking passwords…

March 5, 2021 By Michael Kavka Leave a Comment

The world of cybersecurity understands the need for secure passwords. While passwords with special characters, numbers and both capital and lower case letters help make them more secure, length is a factor. These reasons, alongside with using unique passwords are why we recommend password managers. It has been a long running feud with sites to get them to allow some of these factors, especially Banking sites. The most common things they have issues with is long passwords and special characters, and some of this stems from legacy systems that might still be in production. Mainframes that do the actual work tend to have less secure requirements (I have seen this in many companies that have mainframe systems for specific things).

There is now another issue into the mix, and that is financial software. I recently was trying out Quicken, which I had used years before, to see if I could recommend it to someone I know after they had asked about it. My prior experiences with it had been positive, and I was glad to see that things looked pretty much the same, but updated and a bit easier to use. That was until I went to enter one financial institutions password to get transactions. Quicken itself has decided that you should use only up to a 12 character password (I use much longer ones), and will not work with longer passwords. Not only do they do this, but the error message puts the blame on the financial institutions, which is an outright lie.

When I talked to support they apologized and said there is nothing that can be done at this time to correct the issue. That is their choice, and I will tell the person who asked me about it, not to use it for security reasons at this time. What worries me is the every day person who will believe the lies coming from Quicken on this. The amount of breaches, and security of online accounts, especially financial, is awful, and many banking sites still have issues with MFA (and those that do have MFA force SMS and do not allow for authenticators or Hardware dongles). Having a third party dictate less secure passwords is wrong for overall security.

We have a difficult enough time with security, we do not need companies forcing us to be less secure than we need to be.

Filed Under: Rants, Security, Software Tagged With: Banking, Passwords, Quicken

RSS Taggart Institute Intel Feed

  • Google Chrome to warn users before opening insecure HTTP sites October 28, 2025 Sergiu Gatlan
  • TEE.Fail attack breaks confidential computing on Intel, AMD, NVIDIA CPUs October 28, 2025 Bill Toulas
  • Grokipedia Is the Antithesis of Everything That Makes Wikipedia Good, Useful, and Human October 28, 2025 Jason Koebler
  • Rogue Goodreads Librarian Edits Site to Expose 'Censorship in Favor of Trump Fascism’ October 28, 2025 Matthew Gault
  • New Android malware mimics human typing to evade detection, steal money October 28, 2025
  • Lawsuit against NYPD alleges its surveillance system is unconstitutional October 28, 2025
  • Babcock nears first customer for Nomad AI translation tool October 28, 2025 Gerrard Cowan
  • Google probes exploitation of critical Windows service CVE October 28, 2025 David Jones
  • F5 expects nation-state hack to curb revenues October 28, 2025 Eric Geller
  • Clearview AI sued in Europe over alleged privacy violations October 28, 2025

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP