Standard Bank online banking login

CathJ

Expert Member
Joined
Nov 2, 2005
Messages
3,878
Reaction score
10
Location
Cape Town
Has anyone else noticed that the textbox where you type in your card number no longer supports auto-complete? This is such a pain - now I have to either remember my 18-digit card number, or go fetch my card whenever I want to do some banking :( And then invariably I forget to pick up my card again, leaving it all over the house or at work.

I tried asking Standard Bank about it, and got a lecture on how AutoComplete works, and was told to ask my ISP (?!) if I had any more queries :wtf:

I'm sure someone here used to be a web dev at Standard Bank - can't remember the username, but if you're still around, can you confirm that they did change the textbox?
 
It changed for me as well. Funnily enough, other banks in the world have also done it. It was considered a risk or at least made it easier for the wrong people to login to your account.
Standard is also the target of lots of phishing attacks, so beware of the e-mails doing the rounds. Their recommended security package, Trusteer Rapport , is coming under fire as well, so don't install it right now.

Standard is pretty hopeless when it comes to providing information on security or even preventing it. This is the least they've done.
I've tried to get hold of the Fraud section but failed after speaking to 5 people and getting passed up the line. They just don't call back!
 
Yeah, I get an astonishing number of phishing emails relating to standard bank. Not their fault, but they don't respond to phishing reports... they could at least have an automated reply.

The thing with the autocomplete is that it's actually feels less secure for me - I'm more likely to leave my ATM card lying on my desk at work, or entering the card number to my lastpass account (where, in theory, it could be hacked - and I keep my internet banking PIN and password there too, so then they'd have all the info they need) than just having it on as autocomplete on a secure PC without the PIN and password available.
 
I never used the auto fill option for my banking. It makes a bit of sense to turn it off.

Lounger: Do you have a link for the package under fire statement? I never installed it as I don't like to mess around with any software that is related to my online banking. I want a secure website that is always up and running (dream on with SB). My passwords are very strong and are kept in my head. I never respond to any emails wrt banking or click any links related to banking in emails. Just have to be careful like you should be when you visit an ATM to draw money.

If you haven't been the victim of fraud, don't expect them to help you. They are not the enquiries section, they are very busy dealing with fraud investigations. Try visit a branch near you. I have always left the branch near me in the CBD happy. They are always willing to answer questions that they can and if they can't, refer you to somebody that can.
 
I think the major problem is the system of using 16 digit card numbers rather than profile numbers which are much shorter. I can remember all the shorter profile numbers, pins and passwords for my accounts but can't remember the long card number.

I know these banks use the following:
FNB, Nedbank and Absa use a profile number, pin and password.
Standard Bank and Virgin Money use a card number, pin and password. - WHAT A PAIN


I also didn't install any of the anti-phishing software from either fnb, nedbank or standard bank.
 
I would love to know what exactly the hackers are planning on doing once they have access to my account? Send all my money to one of my beneficaries?

Also, phising aside, if you somehow manage to get a key logger on your system wouldn't it be better to have the information stored in the browser rather than typing it out each time? Does anyone remember when you had to use the on screen keyboard to enter the password? :D
 
Last edited by a moderator:
Surly this makes security sense, no? I prefer not having any of my banking details saved in anyway.

In theory, yes. In practice, though, I autocomplete the card number and save my password and pin in PasswordSafe. So if someone gets my passwordsafe flashdrive and (somehow) hacks it, they don't have my card number; if someone gets onto my pc, they have my card number via autocomplete, but not my pin and password.

Now, because I don't want to go searching the house for my ATM card every time I want to log in, I save my card number in Password safe as well. Which means all the necessary info is available to whoever can hack into my passwordsafe db (unlikely, but still...)
 
I would love to know what exactly the hackers are planning on doing once they have access to my account? Send all my money to one of my beneficaries?

Nope, send it to a third party - and somehow supress the sending of SMS's and OTP requests - this happened to my GF !

And the cops are useless, they refuse to open a case if you can't tell them where the money was stolen :wtf:

And the banks refuse to do anything if you don't open a case first :wtf:

Classic catch 22 ???
 
Last edited:
Security is compromised the minute access codes, passwords or pins or a combination, are so complicated that people write them down because they can't remember them.

Some sites require passwords more complex than banks, and all you can do on them is view.
 
I consider auto-complete a security feature more than a security risk. If I suddenly wake up one morning, stupid, and follow a phishing email link, the browser isn't going to auto-complete the field, so I'm then tipped of to the fraud. This also applies to spelling error attacks (www.standdardbank.co.za) and homograph attacks (www.standàrdbank.co.za). There's enough security focused on passwords, pins and OTPs to prevent a card number from being useful to a criminal, even if he manages to obtain it from a secure PC. And I'm sure that there are easier ways to steal someone's card number than pulling it off a browser, the card number field is in plain text FFS.
 
If you look at the HTML for the SB login page, you'll see the autocomplete=off attribute has been added to the form tag. Dunno how long that's been there.

If you use your ATM card to login to SB you don't need to remember all 18 digits. Ignore the first 6 digits and the last 3. 3 or 4 logins later and you''ll know your number off by heart.

Lounger, do you have a link on the Rapport software coming under fire? I'm using it without any issues.
 
Has anyone else noticed that the textbox where you type in your card number no longer supports auto-complete? This is such a pain - now I have to either remember my 18-digit card number, or go fetch my card whenever I want to do some banking :( And then invariably I forget to pick up my card again, leaving it all over the house or at work.

I tried asking Standard Bank about it, and got a lecture on how AutoComplete works, and was told to ask my ISP (?!) if I had any more queries :wtf:

I'm sure someone here used to be a web dev at Standard Bank - can't remember the username, but if you're still around, can you confirm that they did change the textbox?

Tip: I have a *.txt file with my card numbers and passwords - copy & paste.

I never use auto complete on system, online or on my cellphone. (means if a friend has to use my pc in an emergency very rarely happens)- no auto completes will kick in)
 
"I never use auto complete on system, online or on my cellphone. (means if a friend has to use my pc in an emergency very rarely happens)- no auto completes will kick in)"
Both my wife's computer and mine are password protected on a short auto sleep cycle. If anyone needs to use a computer there is a spare.

(However it is somewhat annoying to be Skyped from the next room!)
 
Nope, send it to a third party - and somehow supress the sending of SMS's and OTP requests - this happened to my GF !

And the cops are useless, they refuse to open a case if you can't tell them where the money was stolen :wtf:

And the banks refuse to do anything if you don't open a case first :wtf:

Classic catch 22 ???

Did you HelloPeter the indecent?
 
Tip: I have a *.txt file with my card numbers and passwords - copy & paste.

I never use auto complete on system, online or on my cellphone. (means if a friend has to use my pc in an emergency very rarely happens)- no auto completes will kick in)

I would never use a .txt file! At the very least use something like PasswordSafe so that your data is encrypted.
 
Changed for me, but I sent an email to my gmail with it in, so its easily searchable for quick copy and paste.
 
I consider auto-complete a security feature more than a security risk. If I suddenly wake up one morning, stupid, and follow a phishing email link, the browser isn't going to auto-complete the field, so I'm then tipped of to the fraud. This also applies to spelling error attacks (www.standdardbank.co.za) and homograph attacks (www.standàrdbank.co.za). There's enough security focused on passwords, pins and OTPs to prevent a card number from being useful to a criminal, even if he manages to obtain it from a secure PC. And I'm sure that there are easier ways to steal someone's card number than pulling it off a browser, the card number field is in plain text FFS.

I agree... If I have to enter my card number then I always think twice about where I am, what I am doing and why its not autocompleting.
 
Top
Sign up to the MyBroadband newsletter
X