in reply to Re: PM password capped at 8 chars?
in thread PM password capped at 8 chars?
The reason that forms that accept passwords only accept 8 characters is more likely that crypt is used to generate login cookies so any characters beyond 8 would be ignored when creating the cookie. But that all is being changed (more slowly than expected or desired, as usual).
Somewhat interestingly, the field in the DB for password is limited to 10 characters. So, if you work around the 8-character limit in the forms, you can set a 9- or 10-character password. Such would make it impossible to log in to the site using the existing forms and then the extra character(s) would be ignored when the cookie was created.
As to why the password field is 10 characters and unhashed, I have no clue and that predates my knowledge of even of the existence of the site by several years.
- tye
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: PM password capped at 8 chars? (or 10)
by bv (Friar) on Aug 31, 2009 at 19:21 UTC | |
by Anonymous Monk on Aug 31, 2009 at 23:24 UTC |