• Ed Wagner - Tuesday, January 16, 2018 11:34 AM

    Luis Cazares - Tuesday, January 16, 2018 8:56 AM

    Sean Lange - Monday, January 15, 2018 10:00 AM

    Gosh that sounds like our payroll system. It does not allow any special characters....nothing other than [a-zA-Z0-9] except it MUST contain a single $, # or !. And it must be exactly 8 characters. No more or less. The rules are so stringent it is isn't even remotely secure. WTF????

    Sounds like the requirements from a bank for their online site. The only difference is that it should be only numbers and exactly 8 digits. I only had an account with them because it was a company policy to receive my paycheck, but I would never get any of their products.

    That's completely pathetic, especially for a bank.  The company should be able to direct deposit to any bank.  Sounds like it's time to get a new bank.

    I don't think a company in the UK could  legally do that - the employee designates where his pay is deposited (subject to court orders, and maybe to regulations issued by the Inland Revenue Service), not the company.
    As for security, yes I have an 8 digit account number.  However,  it doesn't help anyone hack into my account.   To do that they need to have possession of my debit card, know my online scheme membership number, have a one-off password construction device programmed to match the security at the bank's end, and know my PIN for my debit card in order to get the device to construct a one-time password (it incorporates a card interface and requires pin input that the card verifies).  I thought that similar leve lof security as operated now by all UK banks, and would be surprised to find poor online banking security anywhere in within the EU or indeed in India or Lebanon (don't know about the rest of the world, haven't spent enough time there).

    Tom