in reply to Re: PM password capped at 8 chars?
in thread PM password capped at 8 chars?

The reason that forms that accept passwords only accept 8 characters is more likely that crypt is used to generate login cookies so any characters beyond 8 would be ignored when creating the cookie. But that all is being changed (more slowly than expected or desired, as usual).

Somewhat interestingly, the field in the DB for password is limited to 10 characters. So, if you work around the 8-character limit in the forms, you can set a 9- or 10-character password. Such would make it impossible to log in to the site using the existing forms and then the extra character(s) would be ignored when the cookie was created.

As to why the password field is 10 characters and unhashed, I have no clue and that predates my knowledge of even of the existence of the site by several years.

- tye        

  • Comment on Re^2: PM password capped at 8 chars? (or 10)

Replies are listed 'Best First'.
Re^3: PM password capped at 8 chars? (or 10)
by bv (Friar) on Aug 31, 2009 at 19:21 UTC

    Oh dear. I checked my cookie and this is indeed the case.

    $ echo "bv:<last13ofcookie>" > trash $ echo "<mypass>" > trash $ john -w=trash userpass Loaded 1 password hash (Traditional DES [128/128 BS SSE2]) <mypass> (bv) guesses: 1 time: 0:00:00:00 100% c/s: 25.00 trying: <mypass>

    The collapsing views in Recent Threads was nice, but I'm turning off Javascript for perlmonks.org now (Thanks, NoScript!). Are there any plans to rework this system, or am I whining in vain?

    $,=' ';$\=',';$_=[qw,Just another Perl hacker,];print@$_;
      tye said But that all is being changed (more slowly than expected or desired, as usual).

      Your whining has no effect.