3 ms·
I call Hanlon's Razor (on part of this anyway). I suspect it's far more likely that it was a (stupid) business decisions on the password length/characters to re
by sandfox 14y ago
I call Hanlon's Razor (on part of this anyway). I suspect it's far more likely that it was a (stupid) business decisions on the password length/characters to reduce the number of times people would forget their paswords and initiate a password reset. I have tragically come across this many times (and more than once in the UK retail banking sector)
- bigiain 14y agoI'm less inclined to give them the benefit of the doubt. Limited password lengths (shorter than possible DOS attacks attempting to upload megabytes into the password field) mean that either a) you're storing cleartext passwords, or b) your tech people are storing hashed passwords and somebody who doesn't understand web security is in a position of enough control to subvert the decisions of the tech people who _do_ understand how to do things. Either their password storage is insecure, or their marketing/support/management is reducing security by imposing arbitrarily policies on passwords - arbitrarily policies which just happen to look exactly like they're mitigating SQLi and storing passwords as cleartext.