Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Newsgroups | comp.misc |
| Subject | Re: "Please limit your message to 500 characters" |
| Date | 2016-01-22 23:02 +0000 |
| Organization | Piglet's Pickles & Preserves |
| Message-ID | <dgfqo8F97qoU4@mid.individual.net> (permalink) |
| References | <dfo8stFbv96U1@mid.individual.net> <n7r6am$1pa$1@dont-email.me> <dgdahcFk9beU1@mid.individual.net> <n7ru6r$tkt$1@dont-email.me> |
On 2016-01-22, Rich <rich@example.invalid> wrote:
> Sylvia Else <sylvia@not.at.this.address> wrote:
>> On 22/01/2016 4:59 AM, Scott Alfter wrote:
>> > In article <dfo8stFbv96U1@mid.individual.net>,
>
>> > What's worse than that, though, is a password field with a length
>> > limit (especially an absurdly low limit like 8-12 characters).
>> > That they're imposing a length limit on passwords implies that
>> > they're storing passwords directly (DANGER WILL ROBINSON!), not
>> > hashing them and storing the hashes. I prefer to let KeePass
>> > generate 24-32 characters of gibberish to use as a password.
>
>> I've raised that exact issue with a couple of organisations. Never
>> got a response, though.
>
> If their IT guys are incompetent enough to be storing passwords in a
> char(12) or varchar(12) column in their db in the clear, they are
> likely also sufficiently tech/security incompetent to understand why
> that is a bad thing to be doing.
>
> Therefore, they simply did not understand your issue, and ignored it.
More likely their management would not permit them to respond.
When I was working, we'd regularly get emails from people saying things
like "Your website is fucked because $THIS", to which the techie reply was
"You're wrong because $THAT, go away moron", and the management response
was not to respond in any way.
--
Today is Boomtime, the 22nd day of Chaos in the YOLD 3182
I don't have an attitude problem.
If you have a problem with my attitude, that's your problem.
Back to comp.misc | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
"Please limit your message to 500 characters" Sylvia Else <sylvia@not.at.this.address> - 2016-01-14 11:36 +1100
Re: "Please limit your message to 500 characters" Rich <rich@example.invalid> - 2016-01-14 00:57 +0000
Re: "Please limit your message to 500 characters" BartC <bc@freeuk.com> - 2016-01-14 01:33 +0000
Re: "Please limit your message to 500 characters" Rich <rich@example.invalid> - 2016-01-14 02:30 +0000
Re: "Please limit your message to 500 characters" Paul Sture <nospam@sture.ch> - 2016-01-17 16:39 +0100
Re: "Please limit your message to 500 characters" Kees Nuyt <k.nuyt@nospam.demon.nl> - 2016-01-18 01:20 +0100
Re: "Please limit your message to 500 characters" Michael Black <et472@ncf.ca> - 2016-01-13 21:12 -0500
Re: "Please limit your message to 500 characters" scott@alfter.diespammersdie.us (Scott Alfter) - 2016-01-21 17:59 +0000
Re: "Please limit your message to 500 characters" Sylvia Else <sylvia@not.at.this.address> - 2016-01-22 11:13 +1100
Re: "Please limit your message to 500 characters" Rich <rich@example.invalid> - 2016-01-22 00:47 +0000
Re: "Please limit your message to 500 characters" Sylvia Else <sylvia@not.at.this.address> - 2016-01-22 13:54 +1100
Re: "Please limit your message to 500 characters" Huge <Huge@nowhere.much.invalid> - 2016-01-22 23:02 +0000
Re: "Please limit your message to 500 characters" Paul Sture <nospam@sture.ch> - 2016-01-29 10:22 +0100
csiph-web