Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

The one about banking passwords…

Posted on March 5, 2021 By Michael Kavka No Comments on The one about banking passwords…

The world of cybersecurity understands the need for secure passwords. While passwords with special characters, numbers and both capital and lower case letters help make them more secure, length is a factor. These reasons, alongside with using unique passwords are why we recommend password managers. It has been a long running feud with sites to get them to allow some of these factors, especially Banking sites. The most common things they have issues with is long passwords and special characters, and some of this stems from legacy systems that might still be in production. Mainframes that do the actual work tend to have less secure requirements (I have seen this in many companies that have mainframe systems for specific things).

There is now another issue into the mix, and that is financial software. I recently was trying out Quicken, which I had used years before, to see if I could recommend it to someone I know after they had asked about it. My prior experiences with it had been positive, and I was glad to see that things looked pretty much the same, but updated and a bit easier to use. That was until I went to enter one financial institutions password to get transactions. Quicken itself has decided that you should use only up to a 12 character password (I use much longer ones), and will not work with longer passwords. Not only do they do this, but the error message puts the blame on the financial institutions, which is an outright lie.

When I talked to support they apologized and said there is nothing that can be done at this time to correct the issue. That is their choice, and I will tell the person who asked me about it, not to use it for security reasons at this time. What worries me is the every day person who will believe the lies coming from Quicken on this. The amount of breaches, and security of online accounts, especially financial, is awful, and many banking sites still have issues with MFA (and those that do have MFA force SMS and do not allow for authenticators or Hardware dongles). Having a third party dictate less secure passwords is wrong for overall security.

We have a difficult enough time with security, we do not need companies forcing us to be less secure than we need to be.

Rants, Security, Software Tags:Banking, Passwords, Quicken

Post navigation

Previous Post: Holiday CTF review
Next Post: Are you sure it is the execs?

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Attackers conceal phishing lures using invisible Unicode characters September 6, 2026 Bill Toulas
  • NYS Comptroller DiNapoli releases more municipal cybersecurity audits September 6, 2026 Dissent
  • Natural Resources Wales confirms data breach due to human error September 6, 2026 Dissent
  • US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure September 6, 2026 Dissent
  • French Police Arrest Suspected ZeroBytes Hacker Over Tax Data Theft September 5, 2026 Dissent
  • OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure September 5, 2026 Anthony Ha
  • FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor (1) September 5, 2026 Dissent
  • Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain September 5, 2026 Bill Toulas
  • OpenAI admits it didn't disclose rogue AI wiki hijacking incident September 5, 2026 Ax Sharma
  • numbat - AI agent observability, (Fri, Sep 4th) September 5, 2026
  • OpenAI agents discussed ways to escape their sandbox on public wiki September 4, 2026 Dan Goodin
  • European parliament members call for slowdown of Serbia’s EU entry over spyware use September 4, 2026 Tim Starks

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Attackers conceal phishing lures using invisible Unicode characters September 6, 2026 Bill Toulas
  • NYS Comptroller DiNapoli releases more municipal cybersecurity audits September 6, 2026 Dissent
  • Natural Resources Wales confirms data breach due to human error September 6, 2026 Dissent
  • US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure September 6, 2026 Dissent
  • French Police Arrest Suspected ZeroBytes Hacker Over Tax Data Theft September 5, 2026 Dissent
  • OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure September 5, 2026 Anthony Ha
  • FalconFlank Zero-Day Hits CrowdStrike Falcon Sensor (1) September 5, 2026 Dissent
  • Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain September 5, 2026 Bill Toulas
  • OpenAI admits it didn't disclose rogue AI wiki hijacking incident September 5, 2026 Ax Sharma
  • numbat - AI agent observability, (Fri, Sep 4th) September 5, 2026
  • OpenAI agents discussed ways to escape their sandbox on public wiki September 4, 2026 Dan Goodin
  • European parliament members call for slowdown of Serbia’s EU entry over spyware use September 4, 2026 Tim Starks
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.