Hacker News new | past | comments | ask | show | jobs | submit login

From the help page:

"TalkTalk will also NEVER

Send you emails asking you to provide your full password. We will only ever ask for two digits from it to protect your security."

AFAIK, you can't verify two randomly selected characters to a hashed password. My bank is also guilty of this.

Edit: direct evidence from TalkTalk: https://twitter.com/TalkTalkCare/status/514417284560191488?r...




You can achieve this by hashing all the possible combinations that you could ask for with a salt and store those.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: