3 ms·
> Do you really think the only thing the bank does to log people on is to check the username and password? Yes. Yes I do. If you're putting arbitrary limitatio
by NotATroll 7y ago
> Do you really think the only thing the bank does to log people on is to check the username and password?
Yes. Yes I do. If you're putting arbitrary limitations on a user's password length, down to 6 characters even. I see no reason why you wouldn't be equally as insane with the rest of your system.
And, frankly speaking. The whole "you're locked out after 3 attempts" non-sense is complete crap. What is this now? We're supposed to believe databases don't get hacked into, and hashed passwords aren't leaked on the net for countless people to hack at and break?
This sentiment leads me to believe the passwords are stored in plaintext.