FNB blocks users from saving passwords in their browser

So FNB's new mission is to ensure that users accounts get hacked because they can no longer use secure passwords, I fracking love this stupidity. When the eff did Jacob Zuma take over?
 
LOL

Poor RBJACOBS and all the mud on his face....

I am very happy they've rolled back, I suppose they will pretend now that this never happened
 
I've seen a lot of people saying that they use a password manager to autofill, then they either backspace and manually refill, or just add the last character themselves. I tried this, and got a "incorrect password" message. What was interesting was that my LastPass prompted me to update my password thereafter. I tried this, and when I looked at the saved password it was a completely different string.

Has anyone else tried this and experienced similar? I think FNB have found a way around this.

They are swapping your password for a random one and that is why LastPass is updating with some weird value! Check out the javascript: https://fnb.co.za/00Assets/v2.2/js/pilot.js

char4e on Twitter:

Not that it should be necessary, AT ALL, but to allow password managers, simple add http://https://www.fnb.co.za/web-plt/Exhursfl as a blocked url in your ad blocker, or just block https://fnb.co.za/00Assets/v2.2/js/pilot.js
 
LOL

Poor RBJACOBS and all the mud on his face....

I am very happy they've rolled back, I suppose they will pretend now that this never happened
Unless they're just tweaking something - there were a lot of issues with bank feeds etc. I hope this is permanent.
 
When is FNB introducing login 2FA through the web browser?
FNB business accounts can be setup so that you have to verify access via the phone app (which is considerably easier than their default secure cert method).
 
I've noticed the saved passwords I have on the desktop version sync with the mobile version. Presumably if somebody had their password saved on their desktop version of chrome their at risk if somebody steals their Android Phone
 
I've noticed the saved passwords I have on the desktop version sync with the mobile version. Presumably if somebody had their password saved on their desktop version of chrome their at risk if somebody steals their Android Phone
Assuming you have no pin or biometrics security setup on the phone, yes. But then is that any different to leaving a laptop lying around with no login requirement? It's equivalent to leaving your bank card on a table with the ATM pin written on it, IMHO. There's a point beyond which basic levels of security become entirely the client's issue.
 
I got this really doublespeak response from FNB.

FNB recognises the valuable feedback from our customers regarding the measures to prevent auto-filling of banking passwords

We have found that a number of our customers save their banking passwords to their browsers. This places customers with stolen or unattended devices at considerable risk. As a consequence we strongly discourage customers from storing their banking passwords in the their browsers.

FNB recognizes the value of password managers. Whilst we do not discourage customers from using a password manager, customers need to be aware that should their device be stolen or accessed without their permission, a user who gains access to their cloud storage or password saved on the device will be able to login to their banking and perform transactions. The safety and security of all our customers is of paramount importance to us.

We note with concern the recommendation to install unauthorised software and browser extensions by some users in a bid to circumvent the auto-filling of passwords. The use of this type of software for your banking is strongly discouraged as it places the user at a high risk of introducing malicious software onto their device. Alternatively it places users at an increased risk of phishing. As a consequence hereof we have decided to revisit the decision to prevent auto filling of passwords at this time.

Decisions regarding security have to protect all of our customers, in particular the vulnerable. We would like thank our customers in the technology space for their valued contribution and robust engagement in this matter.
 
Top
Sign up to the MyBroadband newsletter
X