The reason that forms that accept passwords only accept 8 characters is more likely that crypt is used to generate login cookies so any characters beyond 8 would be ignored when creating the cookie. But that all is being changed (more slowly than expected or desired, as usual).
Somewhat interestingly, the field in the DB for password is limited to 10 characters. So, if you work around the 8-character limit in the forms, you can set a 9- or 10-character password. Such would make it impossible to log in to the site using the existing forms and then the extra character(s) would be ignored when the cookie was created.
As to why the password field is 10 characters and unhashed, I have no clue and that predates my knowledge of even of the existence of the site by several years.
- tye
In reply to Re^2: PM password capped at 8 chars? (or 10)
by tye
in thread PM password capped at 8 chars?
by bv
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |