ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Password Limitations

    Scheduled Pinned Locked Moved IT Discussion
    insecuresecuritypassword
    18 Posts 6 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @handsofqwerty
      last edited by

      @handsofqwerty said:

      @MattSpeller said:

      One of the banks I use limits you to 8 digits, no special characters or spaces.

      It's.... so wrong.

      Because they like insecure passwords?

      Eight characters is the standard System V limit. A lot of systems inherited from that.

      ? 1 Reply Last reply Reply Quote 0
      • ?
        A Former User @scottalanmiller
        last edited by A Former User

        @scottalanmiller said:

        @handsofqwerty said:

        @MattSpeller said:

        One of the banks I use limits you to 8 digits, no special characters or spaces.

        It's.... so wrong.

        Because they like insecure passwords?

        Eight characters is the standard System V limit. A lot of systems inherited from that.

        Was.. That's been removed for a good while. They supposedly did it some people wouldn't write it down. Most banks I've been around use Jack-Henry stuff on IBM Power systems. Granted I've only done stuff for credit unions.

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @A Former User
          last edited by

          @thecreativeone91 said:

          @scottalanmiller said:

          @handsofqwerty said:

          @MattSpeller said:

          One of the banks I use limits you to 8 digits, no special characters or spaces.

          It's.... so wrong.

          Because they like insecure passwords?

          Eight characters is the standard System V limit. A lot of systems inherited from that.

          Was.. That's been removed for a good while. They supposedly did it some people wouldn't write it down. Most banks I've been around use Jack-Henry stuff on IBM Power systems. Granted I've only done stuff for credit unions.

          It's not been long since I was in banking and there were loads of those still around. Loads. And every bank that I know had the same issues, it wasn't unique. And it takes many, many years to phase out old systems. Considering key systems were still running gear and OSes from 1996, switching soon isn't something that happens.

          ? 1 Reply Last reply Reply Quote 0
          • ?
            A Former User @scottalanmiller
            last edited by

            @scottalanmiller said:

            @thecreativeone91 said:

            @scottalanmiller said:

            @handsofqwerty said:

            @MattSpeller said:

            One of the banks I use limits you to 8 digits, no special characters or spaces.

            It's.... so wrong.

            Because they like insecure passwords?

            Eight characters is the standard System V limit. A lot of systems inherited from that.

            Was.. That's been removed for a good while. They supposedly did it some people wouldn't write it down. Most banks I've been around use Jack-Henry stuff on IBM Power systems. Granted I've only done stuff for credit unions.

            It's not been long since I was in banking and there were loads of those still around. Loads. And every bank that I know had the same issues, it wasn't unique. And it takes many, many years to phase out old systems. Considering key systems were still running gear and OSes from 1996, switching soon isn't something that happens.

            Yeah but that's just because they didn't update the OSes. System V was around until 2004-2006. Seems like they should move to Solaris if they want to keep in Unix systems.

            scottalanmillerS 2 Replies Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @A Former User
              last edited by

              @thecreativeone91 said:

              @scottalanmiller said:

              @thecreativeone91 said:

              @scottalanmiller said:

              @handsofqwerty said:

              @MattSpeller said:

              One of the banks I use limits you to 8 digits, no special characters or spaces.

              It's.... so wrong.

              Because they like insecure passwords?

              Eight characters is the standard System V limit. A lot of systems inherited from that.

              Was.. That's been removed for a good while. They supposedly did it some people wouldn't write it down. Most banks I've been around use Jack-Henry stuff on IBM Power systems. Granted I've only done stuff for credit unions.

              It's not been long since I was in banking and there were loads of those still around. Loads. And every bank that I know had the same issues, it wasn't unique. And it takes many, many years to phase out old systems. Considering key systems were still running gear and OSes from 1996, switching soon isn't something that happens.

              Yeah but that's just because they didn't update the OSes. System V was around until 2004-2006. Seems like they should move to Solaris if they want to keep in Unix systems.

              Often they cannot because they run hardware that is decades old and does not support anything remotely new.

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @A Former User
                last edited by

                @thecreativeone91 said:

                Seems like they should move to Solaris if they want to keep in Unix systems.

                That's the most common culprit. Solaris 2.4 is still rampant in the banking world.

                1 Reply Last reply Reply Quote 0
                • NicN
                  Nic
                  last edited by

                  this guide should help:
                  10296886_718979374812532_2669311640662874218_n.jpg

                  MattSpellerM 1 Reply Last reply Reply Quote 4
                  • MattSpellerM
                    MattSpeller @Nic
                    last edited by

                    @Nic I was going to say there's no amount of Webroot that'll help this but then you posted a good pic and now I feel bad for teasing you.

                    NicN 1 Reply Last reply Reply Quote 1
                    • NicN
                      Nic @MattSpeller
                      last edited by

                      @MattSpeller said:

                      @Nic I was going to say there's no amount of Webroot that'll help this but then you posted a good pic and now I feel bad for teasing you.

                      That's ok, I'm happy to be teased anytime 🙂

                      handsofqwertyH 1 Reply Last reply Reply Quote 3
                      • handsofqwertyH
                        handsofqwerty @Nic
                        last edited by

                        @Nic said:

                        @MattSpeller said:

                        @Nic I was going to say there's no amount of Webroot that'll help this but then you posted a good pic and now I feel bad for teasing you.

                        That's ok, I'm happy to be teased anytime 🙂

                        That could have multiple meanings...just saying...

                        1 Reply Last reply Reply Quote 0
                        • tonyshowoffT
                          tonyshowoff
                          last edited by

                          A lot of places restrict the allowed characters because they're morons who don't understand SQL injection and think it's a way to avoid it. Ideally any character should be allowed that can be transferred over HTTP without breaking the hell out of things, which is everything which can be properly encoded.

                          I do trim passwords though, something old school jackasses think is bad, because after all, if there's a space at the beginning or end of a password, or a newline/return character, it must be on purpose, despite the fact that 99.9999999999% of the time it's because someone copy/pasted the password from an email or something and accidentally added on the space/\r/\n. Of course you can make the argument of never sending a password in an email (and we don't), but tell that to users who will do it all day long.

                          I also wrote a method to deal with "easy" passwords, things like repeating words, pattern recognition for phone numbers, birthdates, etc.

                          1 Reply Last reply Reply Quote 0
                          • 1 / 1
                          • First post
                            Last post