3 ms·
I would bet 99% of this is legacy support. Someone in <insert big company> built an entire system over assuming the password is CHAR(6). Unfortunately these fi
by columbo 13y ago
I would bet 99% of this is legacy support. Someone in <insert big company> built an entire system over assuming the password is CHAR(6).
Unfortunately these fixes aren't always as easy as updating the column and introducing salt/hash. The system could be sending the password in plaintext to multiple sub-systems, it could be used for VOIP services, it could even be used by CSRs to manually update settings on behalf of a user, even better, they might be extracted and emailed as attachments to partner companies. I've seen all of the above done with passwords. Fun stuff.
- ocean12 13y agoArs Technica has been doing a lot of excellent work recently.