<input type="password" maxlength="20"> prevents me from logging into Vanguard
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
<input type="password" maxlength="20"> prevents me from logging into Vanguard
Unofficial Hacker News client; not affiliated with Y Combinator.
walrus01 · · focus · HN ↗
And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: <a href="https://www.reddit.com/r/PersonalFinanceCanada/comments/4t0mlk/bmo_only_allows_6_character_passwords_for_its/" rel="nofollow">https://www.reddit.com/r/PersonalFinanceCanada/comments/4t0m...
For the Americans who might not be aware of what BMO is (it's not some podunk small town bank): <a href="https://en.wikipedia.org/wiki/Bank_of_Montreal" rel="nofollow">https://en.wikipedia.org/wiki/Bank_of_Montreal
andrewstuart2 · · focus · HN ↗
walrus01 · · focus · HN ↗
UqWBcuFx6NV4r · · focus · HN ↗
I agree that it any system that allows this IS almost certainly just storing as plain text, and that it’s bad regardless.
unsnap_biceps · · focus · HN ↗
Atheros · · focus · HN ↗
If the data can be read by so many people in the company that even the customer service people have access, it's functionally not encrypted.
unsnap_biceps · · focus · HN ↗
> provably storing peoples' online banking logins in plaintext in some ancient mainframe database system
Is not about functional encryption but storing directly as plain text.