this post was submitted on 10 Jan 2025
304 points (95.5% liked)
Cybersecurity - Memes
2063 readers
2 users here now
Only the hottest memes in Cybersecurity
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Ya know what's actually even more absurd? The password was truncated on creation. The webpage allowed me to type 36 characters into the field, then only saved the first 30 of them.
I verified the full 36 character password before creating the account, and was immediately met with "wrong password." Noticed the 30 character limit when looking at the password change form, and tried cutting the last 6 characters off my existing password, which unfortunately was successful.
They must have been storing your password in plaintext on their end in order for that to work.
So not only did somebody forget a maxlength=30 on the field, but their validation on the server side was also crap. Genius!