Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
| From | Paul Sture <nospam@sture.ch> |
|---|---|
| Newsgroups | comp.misc |
| Subject | Re: "Please limit your message to 500 characters" |
| Date | 2016-01-29 10:22 +0100 |
| Organization | PostgreSQL and SQLite |
| Message-ID | <eknrnc-e4e1.ln1@news.chingola.ch> (permalink) |
| References | <dfo8stFbv96U1@mid.individual.net> <n7r6am$1pa$1@dont-email.me> <dgdahcFk9beU1@mid.individual.net> <n7ru6r$tkt$1@dont-email.me> <dgfqo8F97qoU4@mid.individual.net> |
On 2016-01-22, Huge <Huge@nowhere.much.invalid> wrote: > On 2016-01-22, Rich <rich@example.invalid> wrote: >> Sylvia Else <sylvia@not.at.this.address> wrote: >>> On 22/01/2016 4:59 AM, Scott Alfter wrote: >>> > In article <dfo8stFbv96U1@mid.individual.net>, >> >>> > What's worse than that, though, is a password field with a length >>> > limit (especially an absurdly low limit like 8-12 characters). >>> > That they're imposing a length limit on passwords implies that >>> > they're storing passwords directly (DANGER WILL ROBINSON!), not >>> > hashing them and storing the hashes. I prefer to let KeePass >>> > generate 24-32 characters of gibberish to use as a password. >> >>> I've raised that exact issue with a couple of organisations. Never >>> got a response, though. >> >> If their IT guys are incompetent enough to be storing passwords in a >> char(12) or varchar(12) column in their db in the clear, they are >> likely also sufficiently tech/security incompetent to understand why >> that is a bad thing to be doing. >> >> Therefore, they simply did not understand your issue, and ignored it. > > More likely their management would not permit them to respond. > > When I was working, we'd regularly get emails from people saying > things like "Your website is fucked because $THIS", to which the > techie reply was "You're wrong because $THAT, go away moron", and the > management response was not to respond in any way. I had this many years ago when testing a new extension to the IF statement in a certain language. Yes I was fully aware that this was still a beta feature but the idiot simply pointed me at the printed manual, which obviously didn't contain the new syntax. He didn't do it politely either. -- An invention needs to make sense in the world in which it's finished, not the world in which it's started. -- Ray Kurzweil
Back to comp.misc | Previous | Next — Previous in thread | Find similar | Unroll thread
"Please limit your message to 500 characters" Sylvia Else <sylvia@not.at.this.address> - 2016-01-14 11:36 +1100
Re: "Please limit your message to 500 characters" Rich <rich@example.invalid> - 2016-01-14 00:57 +0000
Re: "Please limit your message to 500 characters" BartC <bc@freeuk.com> - 2016-01-14 01:33 +0000
Re: "Please limit your message to 500 characters" Rich <rich@example.invalid> - 2016-01-14 02:30 +0000
Re: "Please limit your message to 500 characters" Paul Sture <nospam@sture.ch> - 2016-01-17 16:39 +0100
Re: "Please limit your message to 500 characters" Kees Nuyt <k.nuyt@nospam.demon.nl> - 2016-01-18 01:20 +0100
Re: "Please limit your message to 500 characters" Michael Black <et472@ncf.ca> - 2016-01-13 21:12 -0500
Re: "Please limit your message to 500 characters" scott@alfter.diespammersdie.us (Scott Alfter) - 2016-01-21 17:59 +0000
Re: "Please limit your message to 500 characters" Sylvia Else <sylvia@not.at.this.address> - 2016-01-22 11:13 +1100
Re: "Please limit your message to 500 characters" Rich <rich@example.invalid> - 2016-01-22 00:47 +0000
Re: "Please limit your message to 500 characters" Sylvia Else <sylvia@not.at.this.address> - 2016-01-22 13:54 +1100
Re: "Please limit your message to 500 characters" Huge <Huge@nowhere.much.invalid> - 2016-01-22 23:02 +0000
Re: "Please limit your message to 500 characters" Paul Sture <nospam@sture.ch> - 2016-01-29 10:22 +0100
csiph-web