• einkorn@feddit.org
    link
    fedilink
    English
    arrow-up
    6
    ·
    4 months ago

    And then there are those services that let you enter arbitrarily long passwords in the registration form but only save something like 16 characters.

          • amorpheus@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            4 months ago

            No, that’s the point, you’d never know whether they only validate a subset of the password. Only by testing different variations you would know that less than the whole string still works.

              • amorpheus@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                4 months ago

                I wouldn’t speculate on how common it is but limiting passwords seems to happen more than it should. So maybe many are taking the stealth approach.

                One site I know where this happens (at least I experienced it some years ago) was Blizzard. Found out by sheer luck after I clearly fumbled the end of my password and was logged in regardless.