• einkorn@feddit.org
      link
      fedilink
      English
      arrow-up
      6
      ·
      4 months ago

      And then there are those services that let you enter arbitrarily long passwords in the registration form but only save something like 16 characters.

            • amorpheus@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              edit-2
              4 months ago

              No, that’s the point, you’d never know whether they only validate a subset of the password. Only by testing different variations you would know that less than the whole string still works.

                • amorpheus@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  4 months ago

                  I wouldn’t speculate on how common it is but limiting passwords seems to happen more than it should. So maybe many are taking the stealth approach.

                  One site I know where this happens (at least I experienced it some years ago) was Blizzard. Found out by sheer luck after I clearly fumbled the end of my password and was logged in regardless.