132 points

Their policy should just be to reset the password immediately and have the user set a new one. This is one hell of a risk.

permalink
report
reply
40 points

I still can’t believe American banks lets you login with just username / password? Surely there is some id check or at least two factors involved?

permalink
report
parent
reply
33 points
*

Nope, several years ago someone complained that their steam account has better protection then their bank account. We’re now in 2023 and that statement still holds. It’s quite scary really. Bank websites that heavily rely on third party scripts ,“MFA” logins based on something you know and something you know. Account verification question based on code words or security questions based on public information. Worst of all, the ignorance of it all. “We got hacked, here have a identity protection bandage, comes with an automatic subscription after several years”.

permalink
report
parent
reply
3 points

Yes, they do. Wtf is even happening in this thread.

permalink
report
parent
reply
3 points

I wanted to use a 2FA device for my banking accounts and no bank that I have spoken to would allow it. I’d had a breach on one account because my information had been leaked from several different places including the federal government and a credit agency and as a result the person used my leaked information to validate their way into my checking account. At that point they let me set up a pass phrase and a couple of other random safeguards. This was all well and good but it didn’t make me feel safer than having that account protected by a physical 2FA device. I was also given more free credit monitoring (which I’ve gotten like 4 or 5 times in the last 10 years or so). Still bugs me to this day.

permalink
report
parent
reply
2 points

No wonder all the finance and budget apps primarily prefers integrating with American banks!

permalink
report
parent
reply
5 points

Yeah I’m European end my job in accounting makes me have to work with American banks regularly. So let’s just say my expectations on American banks are quite low.

permalink
report
parent
reply
1 point

Wait, American banks don’t go with extra authentication? I couldn’t log in anywhere without SMS or additional apps or whatever. Depending on your bank you might even have to go through three different stages of authentication. Over the pond you just go username / password?

permalink
report
parent
reply
5 points

I have BofA and my mobile app requires 2fa over SMS.

permalink
report
parent
reply
4 points

Alright, SIM swap it is!

permalink
report
parent
reply
4 points

They don’t, and there is, but you would still suggest removing the user name and password from a social media post anyway. Right?

permalink
report
parent
reply
12 points
*

That would imply they have to test that the credentials are correct though.

Otherwise I can just put somebody’s user and put some fake password and they would reset it and disconnect the account of that user and annoy him.

permalink
report
parent
reply
6 points

But the username is still public, you can change the password but if your customer is idiotic enough to blast both out into the internet, the password will just get a 1 or ! After the password they used before…

permalink
report
parent
reply
27 points

Hot take: let the bank release tweets like this as a honeypot, and see who tries to log in.

permalink
report
reply
19 points

That is one way to get their attention

permalink
report
reply
19 points
*
Deleted by creator
permalink
report
reply
24 points

hunter2

permalink
report
parent
reply
5 points

xxxxxxxxxxxxx

permalink
report
parent
reply
5 points

Shit, it works!

permalink
report
parent
reply
5 points

Qfpdx6vPaF9t5xwvskSNBEjShe7dXJmWwjTeDqm5iesrjfbVpa

Edit: Not for me it doesn’t.

permalink
report
parent
reply
3 points

xxxxxxxxxxxx

permalink
report
parent
reply
2 points

You’re spreading misinformation

permalink
report
parent
reply
14 points
Deleted by creator
permalink
report
parent
reply
7 points

You must be fun at parties.

permalink
report
parent
reply
13 points

Couldn’t BofA Have deleted the tweet?

permalink
report
reply
49 points

I get why you’re saying that since it was Xitted at/tagged Bank of America. But it was still a public post from the user’s account. That’s like assuming a company could delete one of your emails or your Facebook post.

permalink
report
parent
reply
6 points

I never used twitter but I guess the best you can do is make it not appear on your wall but the tweet still exists.

permalink
report
parent
reply
14 points

Tweets from other people don’t ever appear on your wall. They only appear on that user’s profile page, or on the home page of users who follow that user. Or, the third way it can show up is attached to another post that replies to it.

So ironically, by replying and telling the user to remove their personal information, BoA has actually ensured more people are able to see that user’s personal information.

permalink
report
parent
reply
21 points

No, but they could have (and maybe have) block access to their bank account as a precaution.

permalink
report
parent
reply
4 points

They also definetely should have advised them to (or just done it themselves) reset their password, because even deleting the tweet isn’t nearly enough at that point (as evidenced by the screen grab lol

permalink
report
parent
reply

Old People Facebook

!oldpeoplefacebook@reddthat.com

Create post

The sublemmy for “Old People Facebook” is a curated space showcasing the charming, confusing, and often hilarious social media endeavors of the older generation. From accidental memes and cryptic status updates to endearing attempts at using modern technology, this sublemmy celebrates the unique ways seniors engage with the digital world.

Community stats

  • 4

    Monthly active users

  • 108

    Posts

  • 1K

    Comments

Community moderators