edgeblog.net — After Sarbanes-Oxley, PCI, Graham-Leach, and numerous break-ins, major financial companies still get information security basics, such as password management wrong. This article discusses how Charles Schwab's retirement website, schwabplan.com mishandles user passwords. It's a good read about what is wrong on many of today's financial websites.