Path: csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Sylvia Else Newsgroups: comp.misc Subject: Re: "Please limit your message to 500 characters" Date: Fri, 22 Jan 2016 13:54:54 +1100 Lines: 28 Message-ID: References: Mime-Version: 1.0 Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: 7bit X-Trace: individual.net iPC/t51/Yc09PfDLr+TOuA/RBZbn9FAClW4nRWUkh9WA2mZRka Cancel-Lock: sha1:q9ORR0xKxV/KJ1FqCnkcuCpIe10= User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Thunderbird/38.3.0 In-Reply-To: Xref: csiph.com comp.misc:10070 On 22/01/2016 11:47 AM, Rich wrote: > Sylvia Else wrote: >> On 22/01/2016 4:59 AM, Scott Alfter wrote: >>> In article , > >>> What's worse than that, though, is a password field with a length >>> limit (especially an absurdly low limit like 8-12 characters). >>> That they're imposing a length limit on passwords implies that >>> they're storing passwords directly (DANGER WILL ROBINSON!), not >>> hashing them and storing the hashes. I prefer to let KeePass >>> generate 24-32 characters of gibberish to use as a password. > >> I've raised that exact issue with a couple of organisations. Never >> got a response, though. > > If their IT guys are incompetent enough to be storing passwords in a > char(12) or varchar(12) column in their db in the clear, they are > likely also sufficiently tech/security incompetent to understand why > that is a bad thing to be doing. > > Therefore, they simply did not understand your issue, and ignored it. > I think the latter is entirely possible, with the added problem that the person who fields these messages has even less technical understanding, and can't even figure out who to forward it too - hence round file. Sylvia.