So 8 digits or maybe 12 or 16 indicates the system runs on a modified bank by phone system. That also means they have to restrict password characters to things that would work on a phone keypad.
Another place I worked had the same problem with passwords because any password that you use might have to be entered into a handheld scanner in the warehouse. And those handhelds didn’t have full keyboards so you could only use characters that exist on the handheld’s keyboard.
* minimum of 8 characters
* one uppercase and lowercase letter
* one number
* one special character
They should just allow any character instead of requiring characters. At least they allow longer passwords...
I was logging in and sure I typoed my password but it worked.
Then I tried typoing it again and it failed.
Then I started to wonder ... yeah after like 8 characters it just didn't matter.
I emailed them and did not get a response, but to their credit they fixed it within about a month. Maybe that was planned already but at least they fixed it.
A few years later I actually had visibility inside that bank due to my work. There was a whole IT team dedicated to "review this and fix the horrible decisions we made in the past". I didn't have visibility to their web interactions / front end and such but it wouldn't surprise me if that was just as much a project to clean up.
To their credit whenever I talked to the "clean up" type team they were super sharp guys and quite willing to listen to outside vendors (me) who sometimes saw stuff the guys inside maybe didn't.
When all bits have been cleared, remove the logic for inspecting the bit and the mark bit. If that takes too long, force your users to update their password at whatever pace suits you.