I use a password manager to store all my passwords. As such I don’t even know what my passwords are for every single site.
As an example, I just generated 3 random passwords using my password manager
These passwords are near impossible to brute force, or when a database is breached and usernames and passwords are downloaded from other sites, I am safe as I will never reuse a password.
FNB have made a change now (claiming to be doing this for our security) and are forcing me to do one of the following.
- Use a simple password that I can remember – not only is this easy to be brute forced, but I am likely to use this password elsewhere which will result in me being exposed by breached databases.
- Copy and paste my password onto a document / notepad and type it in each time.
- Write my password down somewhere and type it in each time.
B & C makes it very likely that someone can see my password or find it where I have it saved / written down.
FNB have implemented a very poor information security practice here. As such I am quite concerned that FNB does not have security in mind in protecting access to my money.
The IT Community in South Africa have been quite vocal about how bad a move this is. For Reference :
https://mybroadband.co.za/forum/thr...om-saving-passwords-in-their-browser.1041501/
Example of why simple passwords are bad:
https://www.troyhunt.com/only-secure-password-is-one-you-cant/
Who do I need to speak to in order to get FNB to reverse this very poor decision?