Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's nothing, mine's a 5 digit pin code which they only validate 3 of in a random order (to annoy keyloggers, I assume) plus the last 4 digits of my phone number.

Edit: This feels like the scene where Mel Gibson and Rene Russo compare scars in Lethal Weapon 3.



"This feels like the scene where Mel Gibson and Rene Russo compare scars in Lethal Weapon 3."

You might also refer to the scene from Jaws(1975) where Hooper and Quint compare scars: http://www.rowthree.com/2011/10/18/finite-focus-competitive-...


Sounds like AIB. If you use the app they don't even ask for the last 4 digits of your phone number.


Bingo. I wonder what their brute force protection is like, but I'm not going to go pentesting the login of a company I'm in the same legal jurisdiction as.


Well if you don't cross state lines, they're less likely to get the FBI involved...


It's an Irish bank, which means I won't be crossing any state lines ;)


Yeah, similarly, Lloyds/HBOS in the UK do allow you to have a master password but you also need to fill out a "memorable information" where you select 3 random characters from a second password. But you don't type them, you select them from a drop down. I can see how this would annoy the most basic of keyloggers but it is also a UX disaster and not suitable for decent loggers. Pisses me off.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: