Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

even worse when they don't properly enforce it and instead silently truncate it.

There was a PayPal bug just a couple years ago where the reset-password page didn't enforce length like other pages did. So it allowed you to create an otherwise illegal password and then your account is completely locked out (I guess, unless you realized the truncation was happening...)

And so I would reset my password, generate a new one... and it would happen again. Took me a while to realize it was the length and not a special character I added messing up with bad encoding logic or something.



> even worse when they don't properly enforce it and instead silently truncate it

JetBlue truncated to 10, e.g.:

    fly0nJetBlue -> fly0nJetBl
So I can tell you it's even worse when they silently truncate it on save, and on some logins, but not on all logins!


I went through this hell just last week with their terrible website. Jetblue has fallen a gew notches over the years.


Thank you for confirming I'm not crazy. I remember having the same problem a few years back and looking up online if anyone had the same problem as me, but found nothing at the time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: