Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
HSBC Mobile App – Authentication Flaw
4 points by valkyrieuk on Dec 14, 2018 | hide | past | favorite | 2 comments
I discovered a flaw in the UK HSBC Mobile banking app.

Essentially the flaw consisted of being able to authenticate through the mobile app using characters that are not in your password (i.e the wrong password).

I raised this withe HSBC via twitter and this was the response.

"Hi ValkyrieUK, my name's Claire and I'm from the Digital Complaint's Team. Thanks for getting in touch about the concerns you have with our app. We're aware customer's can enter additional characters on to their password and it will be accepted as a successful log on. We don't classify this as a security risk, as your password must still be entered correctly for it to be accepted. I'll certainly record your feedback about this matter though and would like to apologise for any concern caused. Kind regards, Claire"

How can this be correct? They clearly are not following a well proven authentication standard, possibly some kind of REGEX involved.



Confirms they are not salting passwords and probably storing them in plain text. I think the app doesnt allow special charactors in passwords either. They really should be called out over this "security".





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: