4 ms·
No bank should be storing passwords as plaintext, therefore the content of your password should not be their concern.
by drinian 16y ago
No bank should be storing passwords as plaintext, therefore the content of your password should not be their concern.
- bmastenbrook 16y agoI don't think it's just about hashing. When I see restrictions on passwords or other fields, I always assume the worst. If < is not allowed, that's because your password will show up unencoded in HTML somewhere. If $ is not allowed, that's because somebody is afraid that it will actually be treated as a variable reference somewhere. Likewise & or % in URL-encoded data, ' or " in JavaScript, etc. The most universal and silent restriction seems to be on NUL bytes.
- count 16y agoBack-ended by non-RDBMS systems, the banks may be using something like YP or NIS to store passwords so that multiple systems can hit one, central authentication system. NIS had horrible password restriction issues (much like LANMAN).