Unfortunately, Pleo account "passwords" must be exactly 4 characters and can only contain digits.
Yep, you read that right: you cannot setup secure passwords on your Pleo account. This was especially surprising because I chose Pleo specifically because they're one of few banks in the EU that allow you to setup 2FA via TOTP (a very secure option for 2FA indeed).
But if the first factor is so horribly insecure that it has a max characters of 4, then you can hardly consider their services to be protected by two factors. It's basically only one factor.
Advice to management: let your users setup passwords that include all ASCII lower-case latin characters, upper-case latin characters, and numbers. Allow passwords at least up to 256 characters in length.
Date of experience: December 12, 2023
Is this your business?
Claim your listing for free to respond to reviews, update your profile and manage your listing.