FNB blocks users from saving passwords in their browser

I'm going to be ****ed when this is implemented cause I have no frikken idea what my password is. Going to go look if Pc can tell me.

Edit// yeah, it does, I should remember it...I hope:ROFL:
 
Other thing, the way this was implemented a couple of weeks back didn't prevent the browser from storing the password, it only prevented the browser entering the password on subsequent visits. This kind of negates their whole point
 
This was mandatory on FNB site,broke password managers and browser stored password(in chrome at least from testing)
Rolled Back few days later
Yesterday they start putting full screen notices it's coming again - for your security (derp no)

The 1 manual char deleted and readded workaround worked pretty well though

As others have alluded to,this is absolutely the inverse of what it should be for a multitude of reasons
 
FNB need to send one of their security architects to BH, DEF CON or PasswordsCon. People have been preaching about NOT changing passwords regularly and having a password manager forever. Corporates like Microsoft are even supporting it.

But FNB seems to be living in their own universe...
 
Stupid move. Will just make people use less secure passwords. Reminds of sites which tell you what your password should be so your alphanumeric random string is suddenly useless.
 
I'm going to be ****ed when this is implemented cause I have no frikken idea what my password is. Going to go look if Pc can tell me.

Edit// yeah, it does, I should remember it...I hope:ROFL:
I've got a feeling that FNB is going to be down for an extended period while 75% of their user base clicks the forgot password link :eek:
 
All they are doing is trying to push people from using the web browser to the IOS or Android apps.
Less chance of someone clicking a link and getting malware on the mobile devices.
 
Why would anyone be stupid enough to save their password in their browser?!?

Yes, if you are exploited because you are dum enuf (misspelled on purpose) to save your banking logon credentials on the second most thief targeted item on your person, it almost seems just.

My pet peeve is a security flaw I discovered back. When I first activated my phone banking. If autocorrect option is enabled on the standard Google keyboard, the second time you enter your pin it gets added to your currently active dictionary. And yes I am fine posting this here, as I have twice now informed them of said flaw.
 
I haven't used saved password in a browser for years, but I rely heavily on LastPass because my password is min. 12 characters long with all manner of characters.

Sadly all this will do is force the lesser-technology savvy folk to keep their passwords in even more stupid places like Excel docs on the desktop.
 
You can use a password manager with anything you like. Don't think it can be blocked. The built in browser feature can be blocked with JS or field properties afaik.
According to @Sinbad password managers are also blocked.
 
Keep your system clean lol. You might know the rules of engagement today, but cyber security moves with the times. Zero days are a reality.

I have never had a breach in all my years. Simple basic rules on websites and the likes and making sure your security is up to date.
 
This is ****ing idiotic.

So quickbooks can't login to FNB anymore because of the popup.

I have discovered that if you use a password manager (lastpass / onepassword / etc) the message pops up every time you login.

If you do the delete and replace last character it works .

"Let's make our clients have to remember a password to login to banking, password managers are bad mmmkay"

Whichever middle manager came up with this idea should be taken outside and be put down.
 
It highlights the need to replace the password. It's FNB's job to keep their clients secure, not to please the quickbooks users. Passwords are the issue, not FNB.

No FNB is the issue.

So their solution is to suggest users must use a simple password, well as complex as you can remember without having to write it down? That is not a solution.

And part of the offering I signed up for allows for quickbooks to connect.
 
  • Like
Reactions: Swa
I know what Sinbad said, and most of us disagree. I think what he means is that his password manager respects the sites request to not save passwords. You have to override it and save them manually.
What he means is that the site won't allow you to login if you haven't physically typed the login credentials. This is the way it worked when they implemented it a few weeks back
 
Top
Sign up to the MyBroadband newsletter
X