ECB mode is just terrible. As well as these suffix problems, I've seen another example where a company used it to encrypt key-value pair cookies. Of course the keys are always the same...so prefixes were guessable too. And wikipedia has a fantastic example of why its stupid for images:
http://en.wikipedia.org/wiki/ECB_mode#Electronic_codebook_.2...
"Since DES only encrypts in blocks of 64 bits (8 bytes) then encrypting and keeping the length of blocks means that you actually get a very good idea of the length of the password - that is, anything with only one block is a password length between 1 and 8 characters, with two blocks between 9 and 16 characters etc. In addition a password of "1234567812345678" would encrypt into two identical blocks."
In general, using any mode of encryption (rather than hashing) on passwords is dumb. But this is dumber than usual.
I'm not sure if this is the case, but sometimes this has to do with 'backwards compatibility'. I've seen databases where some passwords where MD5, some SHA1, some Bcrypt and so on. The login page then will do something like:
if(checkBcrypt(password)) {
login();
} else if(checkSha1(password) || checkMd5(password)) {
updateDbPassword(password);
login();
} else {
loginError();
}