← Back to context

Comment by S_A_P

10 years ago

A few years ago I discovered that the wells-Fargo website would log you in by typing the correct password and some additional n characters after the password. I reported it to the security group and that still worked until I stopped banking with them a year or so later.

I've heard of systems like these, which would essentially store passwords as n-length strings, and upon registration/verification simply truncate the given string to n characters.