IMS_Blog

Because I forget stuff. Part of norcimo.com

Note: It appears you must have reached this page by a deep level URL. In general this site is currently down and unmaintained. See here

About This Post

Originally posted April 18 2006 at 16:04 under General and Web. 0 Comments. Trackbacks Disabled. Last modified: 18 April 2006 at 17:09

More LloydsTSB

Mood:
Annoyed

a screen shot of the second stage of the LloydsTSB online login process, showing a request for 3 random characters from a phrase, to be entered using drop down lists Having managed to get online banking I remembered the thing which annoyed me from all those years ago. If you read that post you’ll notice I mentioned the “memorable information”. The screenshot shows what the bank does with this. The login process picks 3 random characters from the “information” and asked you to enter them using drop down boxes. Gaahhhh. As I mentioned the “memorable information” is essentially a secondary password (you can’t have spaces for instance). I already have a carefully crafted pretty secure password used for nothing but this sign in process, thank you. The thing about passwords is that once you’ve learned them they become pretty quick to type in. They offer security (when used properly and respected) without getting in the way. Making me suddenly have to stop and think about which character comes where in a second password is just silly. And the entry method is silly. And this “security” is silly (the letters/numbers chosen at this point aren’t obfuscated and there is no distinction between lower and upper case, no way to have a character which isn’t a number or letter). In fact this is entirely pointless. If I already know the first password then I’m going to know this too—I can think of no realistic circumstances where that is not going to be the case. I wish they’d just drop it so that what should be a less than ten second process doesn’t take more than 30 as I sit trying to work things out.

Comments (0):

Post a comment

Name and email address are required. Email address is never shown. If you enter a URL your name will be linked to it (this and other links will have the rel attribute set to contain nofollow). Markup allowed: <a href="" title="" rel=""> <em> <strong> <abbr title=""> <acronym title=""> <p> <br />. Anything else is stripped; please be valid. Single linebreaks automatically convert to <br />, double to <p>'s. Additionally anything that looks like a bare URL should get automagically linked. Many acronyms and abbreviations are also automagically handled.

Please note this blog's comment policy

Trackbacks (0):

Trackback URL: http://www.norcimo.com/MT/mt-tb.cgi/551

Advanced...

This Crazy Fool

Who:
Dr Ian Scott
Where:
Croydon (and Gateshead), United Kingdom
Contact:
ian@norcimo.com
What:
Bullding Services Engineer (EngDesign), PhD in Physics (University of York), football fanatic (Newcastle United), open source enthusiast (mainly Mozilla)

More about me [Disclaimer]

You may subscribe to IMS_Blog using the RSS Feed, the Atom Feed or by email.

Creative Commons License

From April 18 Other Years

© Ian Scott. Powered by Movable Type 3.2. This blog uses valid XHTML 1.0 Strict and valid CSS. All times are local UK time. For further details see the IMS_Blog about page.. All my feeds in one.