Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This story needs to be upvoted 1000 times. Why are financial institution so _bad_ at password policies?


Probably mainframes that they can't get rid of, or systems emulating / used to working with them.


I presume they "can't" because it's too expensive?

How expensive is too expensive for some of the richest companies in the world?


When it costs more than the perceived value of benefits.

"Acceptable risk" is the usual term, I believe.


> Why are financial institution so _bad_ at password policies?

Legacy code written quickly in 1998 and not replaced yet?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: