2 ms·
One that comes to recent memory is Schwab. A few points from this (http://www.jeremytunnell.com/posts/swab-password-policies-and-two-factor-authentication-a-com
by mkobit 11y ago
One that comes to recent memory is Schwab. A few points from this (http://www.jeremytunnell.com/posts/swab-password-policies-and-two-factor-authentication-a-comedy-of-errors http://www.jeremytunnell.com/posts/swab-password-policies-an...) article from December 2014:
> "Schwab.com passwords are limited to eight characters, cannot contain symbols, and are case insensitive. "
> "I now know that on the backend, my secure 16 digit password got stored in the system as only the first eight characters."
> "So what they do is allow UP TO eight characters to represent the password, which is stripped from the contents of the password field. Assuming that the user is activating a token, there will be characters left over. Instead of using the LAST six characters to check the token code, they pull the NEXT 6 characters."
Seems like these companies just do not want to put the effort or deal with the customer pain of updating to a newer model.