Man's 'pants' password is changed


Recommended Posts

A man who chose "Lloyds is pants" as his telephone banking password said he found it had been changed by a member of staff to "no it's not".

Steve Jetley, from Shrewsbury, said he chose the password after falling out with Lloyds TSB over insurance that came free with an account.

He said he was then banned from changing it back or to another password of "Barclays is better".

The bank apologised and said the staff member no longer worked there.

Mr Jetley said he first realised his security password had been changed when a call centre staff member told him his code word did not match with the one on the computer.

"I thought it was actually quite a funny response," he said.

"But what really incensed me was when I was told I could not change it back to 'Lloyds is pants' because they said it was not appropriate.

"I asked if it was 'pants' they didn't like, and would 'Lloyds is rubbish' do? But they didn't think so.

"So I tried 'Barclays is better' and that didn't go down too well either.

"The rules seemed to change, and they told me it had to be one word, so I tried 'censorship', but they didn't like that, and then said it had to be no more than six letters long."

'Very disappointing'

Mr Jetley said he was still trying to find a suitable password which met the conditions.

He said his dispute with the bank started over some travel insurance, but that issue had been dealt with by managers independently.

A statement released by the bank said: "We would like to apologise to Mr Jetley.

"It is very disappointing that he felt the need to express his upset with our service in this way. Customers can have any password they choose and it is not our policy to allow staff to change the password without the customer's permission.

"The member of staff involved no longer works for Lloyds TSB."

Lloyds TSB stressed there was no security lapse in this case.

A spokesperson said: "On the majority of transactions advisors cannot read customers' passwords.

"In this case it was a business banking customer using a system where more than one person from a business can check their balance.

"In these cases an advisor can read the full password.

"But if such customers require more complex transactions, then full security procedures apply and advisors cannot read secure information."

Source: BBC NEWS

Link to comment
https://www.neowin.net/forum/topic/663286-mans-pants-password-is-changed/
Share on other sites

A spokesperson said: "On the majority of transactions advisors cannot read customers' passwords.

"In this case it was a business banking customer using a system where more than one person from a business can check their balance.

It shouldn't matter what type of system they are using, they shouldn't be looking at the passwords.

The call center agent must be told the password. Regardless of how it is stored in the database, the person must tell the agent the password. No encryption or hashing will help you. Since humans constantly record what they hear, while computers can be instructed not to do so, I tend to trust computers more than humans.

This message board, for example, stores MD5 hashes of passwords rather than the plain-text passwords themselves. For example, if your password is doggydoor, your password is represented like d3ed1d27eed8902ee5c6ea79d694b0b9. (That's not technically true since the forum does other things to obscure the password further, but I won't dive into the details here.) When you login and give "doggydoor" as your password, the computer will do the MD5-hash process again, resulting in d3ed1d27eed8902ee5c6ea79d694b0b9, which it compares with the hash stored in the database for your user account. The computer sees that they match and lets you in and promptly forgets that your password is doggydoor.

This approach is helpful because it helps prevent those with access to the database from reading peoples' passwords. It helps prevent, but doesn't prevent entirely, as their ability to figure out the password depends on the complexity of the password in the first place. If you use a single word that can be found in the dictionary, they won't have much trouble figuring out your password. They simply go through the dictionary entries following the MD5-hashing process and continue until they find a matching hash. If your password is complex—combining lowercase letters, uppercase letters, numbers, and symbols, like 6+FxCh%&g—then your password will remain concealed from those with access to the database.

That approach isn't possible with human-to-human authentication though because you must tell the person your password and that person has little to no control over whether they remember the password or not. Steve Jetley learned this the hard way.

Regardless, even though that sort of problem is unavoidable in those cases, the six-letter maximum makes no sense whatsoever. They should never confine a password to a single word you can find in the dictionary and only those with six letters or less. That remove most of the randomness that makes passwords useful. How many words exist in English with six letters or less? Not many, in the grand scheme of things, perhaps a few thousand. Among those few thousand words, which words would a successful business person use? A smaller fraction still. This banking company is practically ensuring that it's possible for outsiders to guess a password. I guess they assume that the fact that they run a bank will scare away most people, thus relying on security through obscurity, but that's just foolish from any perspective.

The spokesperson was right that there was no lapse in security. Unfortunately, he's only right in the sense that there practically wasn't any security practices to lapse from.

It shouldn't matter what type of system they are using, they shouldn't be looking at the passwords.

I guess in the situation that it is a security verification process, and not a physical password you use... then it is allowed

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Age 16, old enough to get a full-time job, your own bank account, a passport, get married, even join the military and go to war. But talking to your friends on the internet? Oh hell no!
    • I remember when all games had demos; it was a normal thing, not a limited time promotion.
    • Forza Horizon 6 gets big bug-fixing and balancing update by Taras Buria Today, Playground Games released a big Forza Horizon 6 update with a long list of fixes, patches, and balancing tweaks that the studio promised earlier. Version 375.327 is now available on Steam, Microsoft Store, and Xbox, offering users improvements for AI, audio, design, performance, road discovery, upgrades, visuals, online play, and more. Some of the most notable changes in the Series 2 update include rebalanced drivatars, particularly their difficulty and race start behavior. As such, the game should be more balanced on higher difficulty levels, and AI cars should not shoot out when the race starts as if they have rocket boosters. Speaking of difficulty, developers nerfed Drag Tires physics for a more expected and realistic behavior. They are no longer the go-to option for record-breaking times in road racing, and all leaderboard entries with drag tires will be removed. Completionists will also be glad to get a new feature that lets you see road discovery percentage in each region, which should make discovering all roads easier while keeping it quite challenging and interesting (I spent quite a long time finding the last road). Festival Playlist is also getting some much-needed fixes, including patches for bugs that allowed completing Seasonal Jobs ahead of time or where weekly challenges would not unlock for some players. Developers will retroactively give reward points to all who could not complete all challenges due to these bugs. Other changes include changes to Horizon Play progression so that it is easier to reach Level 100, audio improvements on lower-spec devices, fixes for visual glitches, including pixelated smoke, and more. Developers also addressed the currently non-working Eliminator, an online mode gamers used to farm credits with a Hummer EV exploit. Playground Games plans to re-enable it soon. As a gesture of goodwill, players will get a free McLaren Sabre. Those who used the exploit will not be banned, but developers plan to roll back credits to a maximum of 10M for all who farmed credits using the exploit. You can find the complete changelog for the latest Forza Horizon 6 update here.
    • "Samsung is shutting down yet another app used by millions" I will fix the clickbait title for you, free-of-charge: "Samsung shutting down it's Max VPN app"
  • Recent Achievements

    • First Post
      Cosminus earned a badge
      First Post
    • One Year In
      ThatGuyOnline earned a badge
      One Year In
    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      483
    2. 2
      +Edouard
      187
    3. 3
      PsYcHoKiLLa
      122
    4. 4
      Steven P.
      85
    5. 5
      neufuse
      73
  • Tell a friend

    Love Neowin? Tell a friend!