Man's 'pants' password is changed


Recommended Posts

A man who chose "Lloyds is pants" as his telephone banking password said he found it had been changed by a member of staff to "no it's not".

Steve Jetley, from Shrewsbury, said he chose the password after falling out with Lloyds TSB over insurance that came free with an account.

He said he was then banned from changing it back or to another password of "Barclays is better".

The bank apologised and said the staff member no longer worked there.

Mr Jetley said he first realised his security password had been changed when a call centre staff member told him his code word did not match with the one on the computer.

"I thought it was actually quite a funny response," he said.

"But what really incensed me was when I was told I could not change it back to 'Lloyds is pants' because they said it was not appropriate.

"I asked if it was 'pants' they didn't like, and would 'Lloyds is rubbish' do? But they didn't think so.

"So I tried 'Barclays is better' and that didn't go down too well either.

"The rules seemed to change, and they told me it had to be one word, so I tried 'censorship', but they didn't like that, and then said it had to be no more than six letters long."

'Very disappointing'

Mr Jetley said he was still trying to find a suitable password which met the conditions.

He said his dispute with the bank started over some travel insurance, but that issue had been dealt with by managers independently.

A statement released by the bank said: "We would like to apologise to Mr Jetley.

"It is very disappointing that he felt the need to express his upset with our service in this way. Customers can have any password they choose and it is not our policy to allow staff to change the password without the customer's permission.

"The member of staff involved no longer works for Lloyds TSB."

Lloyds TSB stressed there was no security lapse in this case.

A spokesperson said: "On the majority of transactions advisors cannot read customers' passwords.

"In this case it was a business banking customer using a system where more than one person from a business can check their balance.

"In these cases an advisor can read the full password.

"But if such customers require more complex transactions, then full security procedures apply and advisors cannot read secure information."

Source: BBC NEWS

Link to comment
https://www.neowin.net/forum/topic/663286-mans-pants-password-is-changed/
Share on other sites

A spokesperson said: "On the majority of transactions advisors cannot read customers' passwords.

"In this case it was a business banking customer using a system where more than one person from a business can check their balance.

It shouldn't matter what type of system they are using, they shouldn't be looking at the passwords.

The call center agent must be told the password. Regardless of how it is stored in the database, the person must tell the agent the password. No encryption or hashing will help you. Since humans constantly record what they hear, while computers can be instructed not to do so, I tend to trust computers more than humans.

This message board, for example, stores MD5 hashes of passwords rather than the plain-text passwords themselves. For example, if your password is doggydoor, your password is represented like d3ed1d27eed8902ee5c6ea79d694b0b9. (That's not technically true since the forum does other things to obscure the password further, but I won't dive into the details here.) When you login and give "doggydoor" as your password, the computer will do the MD5-hash process again, resulting in d3ed1d27eed8902ee5c6ea79d694b0b9, which it compares with the hash stored in the database for your user account. The computer sees that they match and lets you in and promptly forgets that your password is doggydoor.

This approach is helpful because it helps prevent those with access to the database from reading peoples' passwords. It helps prevent, but doesn't prevent entirely, as their ability to figure out the password depends on the complexity of the password in the first place. If you use a single word that can be found in the dictionary, they won't have much trouble figuring out your password. They simply go through the dictionary entries following the MD5-hashing process and continue until they find a matching hash. If your password is complex—combining lowercase letters, uppercase letters, numbers, and symbols, like 6+FxCh%&g—then your password will remain concealed from those with access to the database.

That approach isn't possible with human-to-human authentication though because you must tell the person your password and that person has little to no control over whether they remember the password or not. Steve Jetley learned this the hard way.

Regardless, even though that sort of problem is unavoidable in those cases, the six-letter maximum makes no sense whatsoever. They should never confine a password to a single word you can find in the dictionary and only those with six letters or less. That remove most of the randomness that makes passwords useful. How many words exist in English with six letters or less? Not many, in the grand scheme of things, perhaps a few thousand. Among those few thousand words, which words would a successful business person use? A smaller fraction still. This banking company is practically ensuring that it's possible for outsiders to guess a password. I guess they assume that the fact that they run a bank will scare away most people, thus relying on security through obscurity, but that's just foolish from any perspective.

The spokesperson was right that there was no lapse in security. Unfortunately, he's only right in the sense that there practically wasn't any security practices to lapse from.

It shouldn't matter what type of system they are using, they shouldn't be looking at the passwords.

I guess in the situation that it is a security verification process, and not a physical password you use... then it is allowed

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • You can enable the Nova redesign in Firefox 152, under about:config
    • As long as Manifest v2 extensions keep working. I always enable compact mode from about:config. I hope I won't have to switch to LibreWolf or WaterFox anytime soon.
    • Threads scales past half a billion users, brings deeper community and feed controls by Fiza Ali Meta has announced Threads crossing a major milestone of 500 million monthly active users. And, at the heart of this growth sits something simple: communities. From books to basketball, parenting to music, Threads says its rise has been powered by people clustering around shared interests and, in turn, giving the platform its identity. In response, the platform is expanding its Communities feature beyond beta and introducing a set of new tools designed to make participation easier and more engaging. A redesigned Communities Hub will now appear in the main navigation menu, allowing users to jump between groups without leaving their feed. Each community will also receive a distinct Community Icon, giving them clearer visual identity and making them easier to recognise across the platform. Then there’s Community Progress, which is a kind of live gauge showing how close a topic is to becoming a full-fledged community, alongside guidance on how users can contribute to its development. In addition, Meta is also expanding its Community Champions programme, recognising more users who actively contribute to community engagement. And then things go more local; Local Communities is already available in 100 countries, including North America, South America, Asia, and Europe but are now rolling out with native-language tags starting in Japan, South Korea, and Taiwan. The platform is also expanding Live Chats to more communities in the coming weeks, adding features such as co-hosting and the ability to quote moments directly into users’ feeds. Beyond communities, Meta is tightening the loop between users and their feeds. Earlier this year came "Dear Algo," a feature that lets people tell Threads what they want more or less of. Now it’s being paired with a new tool, "Your Algo." It allows people to adjust how frequently certain topics appear, with options lasting one, three, or seven days. Meta says these preferences remain private and can be managed alongside “Dear Algo” in a unified settings hub. The rollout begins in the US, Canada, UK, Australia, and New Zealand. Finally, the company says these changes are part of an ongoing effort to refine Threads based on user feedback and that further updates will continue as the platform evolves.
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      520
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      110
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!