Archive for category 'madness'

AOL's absurdly bad password system


Issues apparently include:

  • Passwords truncated to the first 8 characters
  • Non-alphanumeric characters stripped
  • Stored encrypted (not hashed) in the Windows registry

And various Unix flavours have similar default behaviour?!

