Once again...this would not be a security issue, until you h@x0rs made a big deal out of it... We make people super-duper promise not be bad on our site... What else can we do?
We have something very similar where I work with a time-writing app. It wont let you have a long password, and you have to use alphanumeric only. Great system.
It's pretty crazy how often you run into this. I've even seen it on things like domain registration and control, although I haven't run into it on any sites like this one where it's something like your finances that are at risk.
Sounds like a good ol mainframe character limit
ReplyDeleteThis comment has been removed by the author.
ReplyDeleteI ran into this too a few months ago: here.
ReplyDeleteOnce again...this would not be a security issue, until you h@x0rs made a big deal out of it...
ReplyDeleteWe make people super-duper promise not be bad on our site...
What else can we do?
We have something very similar where I work with a time-writing app. It wont let you have a long password, and you have to use alphanumeric only. Great system.
ReplyDeleteno more than 8 chars and NO SPECIAL chars... that drops the possible keyspace down to about a 10 minute dictionary attack ;) woohoo!
ReplyDeleteIt's pretty crazy how often you run into this. I've even seen it on things like domain registration and control, although I haven't run into it on any sites like this one where it's something like your finances that are at risk.
ReplyDeleteone of the reasons I no longer have an Amex.
ReplyDeleteBy the way... almost a year later and this still hasn't changed.
ReplyDelete