'john@doe.com '
resulting in errors like 'invalid email'. Since whitespaces are invisible to users, they can't figure out what's wrong.
'john@doe.com '
resulting in errors like 'invalid email'. Since whitespaces are invisible to users, they can't figure out what's wrong.
While it technically might make passwords very slightly less secure, it makes life much easier for users, so I personally think it's worth the cost.
We also implemented it at Pinterest, I think it's a pretty good idea for a few common cases, especially for users typing their password on mobile.
Before doing this though, you want to make sure you have rate limits in place against brute force password checks for account takeover.
basically the hashing algorithm they use strips out certain information, which means that e.g.
"PaSSWord123" "pAsswORD123" "PaSSWord123 " etc
all hash to the same value, and so are equivalent.
Wow - non-case-sensitive passwords seem like a bad idea...
How is "flipping all the character's case" different from case-insensitive?
So, if your password was:
fishCAT
They would accept fishCAT, and also FISHcat and FishCAT, and that's it.