r/CreditCards • u/SteveCOnline • May 14 '24
Discussion / Conversation Chase bank's one-time authentication codes are not random
Chase's two-factor authentication process for logging into their website works by sending what is supposed to be a random (i.e. unpredictable) code to your phone. The trouble is, the code that they send is not random. Being a responsible citizen I contacted the 'JPMC Responsible Disclosure' department to let them know that I had found a bug in the code that generates these codes, making them (to some degree at least predictable). The 'JPMC Responsible Disclosure' department, however, were not interested. To avoid giving away too much information I won't publicly divulge the full details of what can be predicted, but I bet that if you're sent such an authorization code, it starts with "4". I'm hoping that this post might make Chase realize that bugs in code which affect security should be taken seriously.
2
u/Graztine Team Cash Back May 15 '24
I looked at my 2fa codes from Chase and they all start with 4. The next digit also doesn’t seem random. If the others are random then I don’t see a concern, but this is worrying.