Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      South Africa tables Starlink-friendly policy shift

      23 May 2025

      Computex 2025 – key takeaways from Asia’s biggest AI tech show

      23 May 2025

      Iqbal Survé’s Sekunjalo moves to delist controversial Ayo Technology

      23 May 2025

      US banks exploring launch of jointly developed stablecoin

      23 May 2025

      Apple smart glasses could be here next year

      23 May 2025
    • World

      iPhone designer Jony Ive to build AI devices with OpenAI

      22 May 2025

      First AI-generated drugs could go on sale by 2030

      22 May 2025

      Google, Volvo deepen partnership on car software

      21 May 2025

      Microsoft pushes for industry standards in AI agent collaboration

      19 May 2025

      Microsoft to lay off 3% of workforce in organisation-wide cuts

      14 May 2025
    • In-depth

      Sam Altman and Jony Ive’s big bet to out-Apple Apple

      22 May 2025

      South Africa unveils big state digital reform programme

      12 May 2025

      Is this the end of Google Search as we know it?

      12 May 2025

      Social media’s Big Tobacco moment is coming

      13 April 2025

      This is Europe’s shot to emerge from Silicon Valley’s shadow

      10 April 2025
    • TCS

      TCS | Reserve Bank fintech head Lyle Horsley on the G20 TechSprint

      22 May 2025

      TCS+ | Schneider Electric’s Clive Roberts on driving digitisation in the CPG sector

      22 May 2025

      TCS | Dalene Steyn on Capitec’s ambitious mobile gameplan

      21 May 2025

      Meet the CIO | Schalk Visser on Cell C’s big tech pivot

      13 May 2025

      TCS | Kiaan Pillay on fintech start-up Stitch and its R1-billion funding round

      7 May 2025
    • Opinion

      Solar panic? The truth about SSEG, fines and municipal rules

      14 April 2025

      Data protection must be crypto industry’s top priority

      9 April 2025

      ICT distributors must embrace innovation or risk irrelevance

      9 April 2025

      South Africa unprepared for deepfake chaos

      3 April 2025

      Google: South African media plan threatens investment

      3 April 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SkyWire
      • Solid8 Technologies
      • Tenable
      • Vertiv
      • Videri Digital
      • Wipro
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Information security » FNB backs down on password decision after backlash

    FNB backs down on password decision after backlash

    By Duncan McLeod20 August 2019
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    First National Bank has suspended its decision to require users to type in their usernames and passwords manually for online banking rather than using their browser or password manager to automatically fill in the fields.

    The move follows a backlash from tech-savvy consumers and security experts who warned that the decision to disallow password managers went against information security best practice. The decision drew fire from well-known infosec expert Troy Hunt and others. FNB appears to be particularly concerned about users installing browser extensions designed specifically to circumvent the ban on the auto-filling of passwords.

    TechCentral tested the online banking service after the statement was e-mailed and can confirm that password managers (the publication used Dashlane in its test) can again be used to auto-fill the username and password fields on the bank’s website.

    FNB recognises the valuable feedback from our customers regarding the measures to prevent auto-filling of banking passwords

    In a statement in response to a column by Alistair Fairweather, published earlier on Tuesday on TechCentral, head of digital banking Giuseppe Virgillito said FNB “recognises the valuable feedback from our customers regarding the measures to prevent auto-filling of banking passwords”.

    Fairweather wrote of FNB’s decision: “By essentially forbidding me to paste my own password into my own browser, FNB has forced me to make a ridiculous choice: either stop using Internet banking (not happening) or change my password to something I can actually remember and type out (in other words something much less secure). And never mind the fact that my password manager is a password-protected, military-grade encrypted vault, which is arguably more secure than most of FNB’s own servers.”

    ‘Considerable risk’

    Virgillito said the decision to prevent the auto-filling of passwords was done with customer security in mind. He said the bank found that “a number of our customers save their banking passwords to their browsers. This places customers with stolen or unattended devices at considerable risk. As a consequence, we strongly discourage customers from storing their banking passwords in their browsers.”

    He said decisions regarding security must protect all its customers, “in particular the vulnerable”.

    Virgillito said: “FNB recognises the value of password managers. While we do not discourage customers from using a password manager, customers need to be aware that should their device be stolen or accessed without their permission, a user who gains access to their cloud storage or passwords saved on the device will be able to log into their banking and perform transactions. The security and privacy of our customers’ banking and login information is of paramount importance to us.

    “We note with concern the recommendation to install unauthorised software and browser extensions by some users in a bid to circumvent the auto-filling of passwords. The use of this type of software for your banking is strongly discouraged as it places the user at a high risk of introducing malicious software onto their device.

    “Alternatively, it also places users at an increased risk of phishing. As a consequence hereof, we have decided to revisit the decision to prevent auto-filling of passwords at this time.”  — © 2019 NewsCentral Media



    Alistair Fairweather Dashlane FNB Giuseppe Virgillito top Troy Hunt
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleFNB’s new password policy makes its customers less secure
    Next Article Spacewalking astronauts add parking spot to space station

    Related Posts

    Economic growth could triple this year: Absa

    26 March 2025

    Hyper-personalisation is next up in eBucks, Pick n Pay pact

    18 March 2025

    Pick n Pay strikes back at Checkers with eBucks deal

    27 February 2025
    Company News

    Kredete launches Africa’s first stablecoin-backed credit card

    23 May 2025

    Surface Copilot+ PCs for business: the future of work, powered by AI

    23 May 2025

    Turbocharge your business operations with a fibre internet line

    23 May 2025
    Opinion

    Solar panic? The truth about SSEG, fines and municipal rules

    14 April 2025

    Data protection must be crypto industry’s top priority

    9 April 2025

    ICT distributors must embrace innovation or risk irrelevance

    9 April 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2025 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.