FNB blocks users from saving passwords in their browser

So as of today I had to ****ing copy and paste my password into a Word Document so I could read it and type it out.

JESUS CHRIST FNB?

Are you literally employing the most useless IT security people ever?
Yep I can confirm my browser changed TODAY as well. They've been warning about it for a while...

FNB is getting their cyber security input from a 1990's BBS.
 
I am honestly ****ing shocked. They insist that I change my password to something I can remember.

Let's ignore the fact that a simple keylogger is a much greater risk than my password manager being compromised but no.... Let's make people manually type their passwords each time


Does anyone here bank with the other banks? Think it is time to change? Who should I move to?
 
I am honestly ****ing shocked. They insist that I change my password to something I can remember.

Let's ignore the fact that a simple keylogger is a much greater risk than my password manager being compromised but no.... Let's make people manually type their passwords each time


Does anyone here bank with the other banks? Think it is time to change? Who should I move to?
Just learn the last character of the password and delete and retype it. That seems to beat their restriction
 
So basically FNB wants recycled, easy to remember, passwords. Why doesn't this instil me with confidence... Pa55wordFNBSux
 
I am honestly ****ing shocked. They insist that I change my password to something I can remember.

Let's ignore the fact that a simple keylogger is a much greater risk than my password manager being compromised but no.... Let's make people manually type their passwords each time


Does anyone here bank with the other banks? Think it is time to change? Who should I move to?
Capitec

Just learn the last character of the password and delete and retype it. That seems to beat their restriction
Easier way is to type an extra character and delete it.
 
I support blocking browser "save password features" but not password managers we are trying to move people away from user created passwords.

Edit: They should have given us 2FA instead.
 
Last edited:
I support blocking browser "save password features" but not password managers we are trying to move people away from user created passwords.

Edit: They should have given us 2FA instead.
There is already 2fa on any transactions
 
It did, it does not anymore...
I see that now. I played around with my password manager on the FNB site and noticed that trying to save my password in the password manager stores a random password in the password field, so now I need to use a PW I can remember, which is certainly far less secure than the one I had... Well done FNB, well done.
 
Can't Mybb do an article / expose / contact someone important at FNB and make them explain?
 
**** sakes, now my password manager also not working. Retyping the last char doesn't work either.
Good luck at me now typing my 20 character random password without errors.
 
This was an issue in 2015 and it's still just as useless at preventing malware as it was before.


Generally, when a whole host of industry experts tell you you're being stupid, it's a good idea to not carry on being stupid.
 
A letter I sent to FNB

I use a password manager to store all my passwords. As such I don’t even know what my passwords are for every single site.



As an example, I just generated 3 random passwords using my password manager





These passwords are near impossible to brute force, or when a database is breached and usernames and passwords are downloaded from other sites, I am safe as I will never reuse a password.



FNB have made a change now (claiming to be doing this for our security) and are forcing me to do one of the following.

  • Use a simple password that I can remember – not only is this easy to be brute forced, but I am likely to use this password elsewhere which will result in me being exposed by breached databases.
  • Copy and paste my password onto a document / notepad and type it in each time.
  • Write my password down somewhere and type it in each time.
B & C makes it very likely that someone can see my password or find it where I have it saved / written down.



FNB have implemented a very poor information security practice here. As such I am quite concerned that FNB does not have security in mind in protecting access to my money.



The IT Community in South Africa have been quite vocal about how bad a move this is. For Reference : https://mybroadband.co.za/forum/thr...om-saving-passwords-in-their-browser.1041501/



Example of why simple passwords are bad:

https://www.troyhunt.com/only-secure-password-is-one-you-cant/



Who do I need to speak to in order to get FNB to reverse this very poor decision?
 
Top
Sign up to the MyBroadband newsletter
X