FNB blocks users from saving passwords in their browser


The OTP was systematically replaced with inContact, which has evolved a bit since 2012. Though inContact is a move into the right direction it doesn’t resolve that my FNB web browser login is still not secure within a good practice. TOTP should be the bare minimum when logging into your account.

The FNB Banking App, which is an inContact mechanism, does have additional securities when logging.

To have something like a TOTP is a consumer’s choice and this is something that FNB has been ignoring. Yes, they are ignoring their customers.
 
I believe this has now also stopped 22Seven from working.

It's also stopped Xero working too. We can't sync our FNB business accounts with Xero anymore. This will affect any 3rd-party accounting tools that get live bank feeds in from FNB. Sage, Quickbooks, etc are all affected. What a f-up...
 
Getting errors inputing my password today and attached errors when trying to log in.
 

Attachments

  • ECUefYKXoAAXZ5x.png
    ECUefYKXoAAXZ5x.png
    29 KB · Views: 25
OK so now FNB is not letting me use my random 28 characters LastPass Generated password to log into FNB via LastPass. So what I have to change my password to Welcome2@ now so I can remember my password. I agreed don't use the browser saved Password but allow LastPass or at least copy or paste from LastPass.

This is a dumb ass move.
 
It's also stopped Xero working too. We can't sync our FNB business accounts with Xero anymore. This will affect any 3rd-party accounting tools that get live bank feeds in from FNB. Sage, Quickbooks, etc are all affected. What a f-up...
This will be a cluster**** for accounting software that uses live bank feeds. Most are through a UK company called Yodlee.

We are using them and will contact them to see if they have a work around for this. Live Bank feeds are critical for us when you have hundreds of transaction daily and importing ofx files are going to add extra time to processing bank transactions.
 
This will be a cluster**** for accounting software that uses live bank feeds. Most are through a UK company called Yodlee.

We are using them and will contact them to see if they have a work around for this. Live Bank feeds are critical for us when you have hundreds of transaction daily and importing ofx files are going to add extra time to processing bank transactions.
I guess 22seven will also be affected. They also use Yodlee.
 
This will be a cluster**** for accounting software that uses live bank feeds. Most are through a UK company called Yodlee.

We are using them and will contact them to see if they have a work around for this. Live Bank feeds are critical for us when you have hundreds of transaction daily and importing ofx files are going to add extra time to processing bank transactions.

Good news, our Xero feeds have started working again. They've obviously fixed the issue, at least as far as live feeds are concerned. I see 22Seven is working too again.
 
I've seen a lot of people saying that they use a password manager to autofill, then they either backspace and manually refill, or just add the last character themselves. I tried this, and got a "incorrect password" message. What was interesting was that my LastPass prompted me to update my password thereafter. I tried this, and when I looked at the saved password it was a completely different string.

Has anyone else tried this and experienced similar? I think FNB have found a way around this.
 
OK so now FNB is not letting me use my random 28 characters LastPass Generated password to log into FNB via LastPass. So what I have to change my password to Welcome2@ now so I can remember my password. I agreed don't use the browser saved Password but allow LastPass or at least copy or paste from LastPass.

This is a dumb ass move.
When I called the Online Banking support to voice my frustrations or concerns, the lady said I'm the only person to complain, and they've had no other concerns from other callers. I think they're delusional.
 
I've seen a lot of people saying that they use a password manager to autofill, then they either backspace and manually refill, or just add the last character themselves. I tried this, and got a "incorrect password" message. What was interesting was that my LastPass prompted me to update my password thereafter. I tried this, and when I looked at the saved password it was a completely different string.

Has anyone else tried this and experienced similar? I think FNB have found a way around this.

I've experienced the exact same thing. Thought I was going crazy. It looks as if when you cut and paste your password they are intentionally garbling the password. After I pasted my password, deleted the last letter and then retyped it, I also got the incorrect password message.
 
So one of two things happened here:

1. QA just followed test steps like robots and didn't raise a fuss about how monumentally retarded it is to try force a handrolled security mechanism that isn't a global norm and has far reaching implications for 3rd party integration as well as introducing new attack vectors like keyloggers on users who previously had strong passwords.

2. Managers (Project, Product, Risk & Compliance, etc.) bulldozed this disaster of a feature through on the basis that it 'improves security' without really understanding anything about user behaviour or any concerns about the undesired effects this may have.
 
Getting errors inputing my password today and attached errors when trying to log in.
LOL. So they don't allow pasting passwords, but leave informative error handling messages on? OWASP Top Ten A6
 
Top
Sign up to the MyBroadband newsletter
X