Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have the memorable phrase and have to use the HSBC app for my password. Now, the fun thing is that my actual HSBC password is 40 characters randomness, so pretty secure. The mobile password that is used to derive the 2FA key must not be longer than 8 characters. So essentially I traded a long and secure password for an 8 character password.

I really really dislike HSBCs online banking as a whole, the password system plus the constant “We encountered an error, please try again later” messages.



Plus the unintuitive navigation, the ridiculous over-skeuomorphism of 'past statements', and the insanely-low, seemingly non-configurable session timeout. At least you can finally use a payment reference > 10 characters, but HSBC's online banking is still stuck in the stone-age overall.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: