It's 2013. Why are there still constraints on what characters can be use for a password?
I would love to hear from the author why this is the case.
It's 2013. Why are there still constraints on what characters can be use for a password?
I would love to hear from the author why this is the case.
Was a lot of fun talking to the customer service rep who insisted I needed to be using IE. That I had to register. That I "must be doing something wrong". That I am not typing in the correct password. That I'm not technically capable.
Turned out to be a length restriction. It just cut off the last n characters of the password I chose. Good times.
Turns out it was ten. Ten characters protecting my sensitive personal banking information. Upon e-mailing, they said they're going to be bumping it to 20.
Ran into a problem a few months ago where I changed my password successfully on the front-end, but one-or-many backend syncing operations mangled the new password by dropping the last n characters on the floor. So when I logged into the front end, it would look like everything was fine until I tried to perform some kind of operation. At which point it promptly threw up all over itself.
Left me in a completely non-working state for a few days. Didn't help that I'm basically the only admin for said system.
It seems concerning that between entering and hash/(b/s)crypt-ing passwords there would be any step which required these limitations. A regex or similar validator on strength not equipped or written to handle other characters? Either way... really?