FNB blocks users from saving passwords in their browser

It's not rolled out yet.
I had a preview of it because reasons.

Lastpass does not work. It uses some sort of Javascript to detect whether keys were pressed, specifically meta keys, and Lastpass does not simulate keypresses.
 
Bitwarden still auto-fills just fine. If they find a way to prevent any sort of auto-fill/pasting of passwords then passwords will get less secure, as users cannot then rely on 30 character strings of nonsense from a password manager.
 
It's not rolled out yet.
I had a preview of it because reasons.

Lastpass does not work. It uses some sort of Javascript to detect whether keys were pressed, specifically meta keys, and Lastpass does not simulate keypresses.

This is disappointing to hear. What idiot made this decision? Password managers have been a thing for how many years.

Thanks for making the point to them. I hope they see reason.
 
This is disappointing to hear. What idiot made this decision? Password managers have been a thing for how many years.

Thanks for making the point to them. I hope they see reason.

Also correct me if I'm wrong - but password managers help in the event that you have a key logger on your PC, i.e. the auto fill is generated from the manager. So forcing people to type out their passwords will make it less secure in this case as well?
 
Also correct me if I'm wrong - but password managers help in the event that you have a key logger on your PC, i.e. the auto fill is generated from the manager. So forcing people to type out their passwords will make it less secure in this case as well?
True.

My understanding is that there's a fraud vector in the wild that targets clipboard / cut and paste. I don't have any more details on it though.
 
For (1) at least, they definitely do try that. They also realize that importing the necessary skills grows industries in their entirety, creating more work for their citizens
Better yet, why wasn't this done earlier
Last pass is also blocked.
Lastpass works just fine with FNB. There is no way a website can block Lastpass.
Just tested with Chrome and Safari and it happily used saved passwords, even though I got the splash screen on Chrome.

Blocking apps like lastpass would just be stupid.

I suspect it will be blocked because most of these password managers use the browser plugin to insert data into the text field. So yah.. I reckon they disabled pasting? And/or insertion via browser.. curious about iOS as this happens on a O/S level.
 
I am hoping they commit to the "smart device" as a primary where by you can generate a login via that.. else this change will be bad as people will use simple passwords which opens up more problems.
 
They trialed this a couple of weeks ago and it broke my 1Password. I found a work around though by having 1password complete the details and then I manually delete and type the last character of the pw. This seemed to beat their system
 
I suspect it will be blocked because most of these password managers use the browser plugin to insert data into the text field. So yah.. I reckon they disabled pasting? And/or insertion via browser.. curious about iOS as this happens on a O/S level.

If they block all PW managers it'll be really stupid...seriously.

They trialed this a couple of weeks ago and it broke my 1Password. I found a work around though by having 1password complete the details and then I manually delete and type the last character of the pw. This seemed to beat their system

Haha, this makes sense as how are they suppose to know you typed in your full password? Makes the whole thing even more silly
 
Good. At least try remember your banking password can't save everything

How is it good? Does the password you remember resemble this:

5GK%U5$vMinY92urn&9TD#Jj8KYrN5

My passwords are randomly generated 30-character strings, stored and used securely with the Bitwarden password manager. It's so secure that Bitwarden requires my physical YubiKey two-factor authentication key to be used whenever I log in. It can plug into a USB port or use NFC on a mobile device, so it is required on all platforms.

But you'd rather we all remember 'horsebatterystaple' instead to improve security?
 
How is it good? Does the password you remember resemble this:

5GK%U5$vMinY92urn&9TD#Jj8KYrN5

My passwords are randomly generated 30-character strings, stored and used securely with the Bitwarden password manager. It's so secure that Bitwarden requires my physical YubiKey two-factor authentication key to be used whenever I log in. It can plug into a USB port or use NFC on a mobile device, so it is required on all platforms.

But you'd rather we all remember 'horsebatterystaple' instead to improve security?
I'm talking about saving in the browser specifically
 
How is it good? Does the password you remember resemble this:

5GK%U5$vMinY92urn&9TD#Jj8KYrN5

My passwords are randomly generated 30-character strings, stored and used securely with the Bitwarden password manager. It's so secure that Bitwarden requires my physical YubiKey two-factor authentication key to be used whenever I log in. It can plug into a USB port or use NFC on a mobile device, so it is required on all platforms.

But you'd rather we all remember 'horsebatterystaple' instead to improve security?

So what I usually do is store the random generated string in the password manager.. and then add an additional string to it which i remember and is not stored anywhere except my brain :p.

This means for important login accounts like bank etc the password manager basically gives u 1 part of 2. Sometimes i interleave this extra bit in part 1 too.. so yah..
 
How is it good? Does the password you remember resemble this:

5GK%U5$vMinY92urn&9TD#Jj8KYrN5

My passwords are randomly generated 30-character strings, stored and used securely with the Bitwarden password manager. It's so secure that Bitwarden requires my physical YubiKey two-factor authentication key to be used whenever I log in. It can plug into a USB port or use NFC on a mobile device, so it is required on all platforms.

But you'd rather we all remember 'horsebatterystaple' instead to improve security?
Hey now, stop giving out my passwords like that!!
/me mutters about needing to change horsebatterystaplecorrect on all systems :(
 
Why would anyone be stupid enough to save their password in their browser?!?
Why are they stupid enough to ask for your full password every time:confused:keyloggers must have a field day.

Could have just made a system asking for random characters of the password each time?
 
Last edited:
This is when you rely on so called "security experts" who don't have a clue as to how people actually use these systems. Causing people to be unable to easily fill in COMPLEX PASSWORDS into the field (such as via a password manager) means that people will instead have to rely on remembering SIMPLE PASSWORDS. This does nothing but reduce password security as most people will resort back to just storing their passwords on pieces of paper or reusing passwords they already use elsewhere.
 
Top
Sign up to the MyBroadband newsletter
X