57
submitted 1 day ago* (last edited 19 hours ago) by NullNet@lemmy.blahaj.zone to c/cybersecurity@infosec.pub

Small rant incomming. I just went to look at applying to Walmart, and when going to make an account their password requirements were 8-11 characters. What kinda nonsense is that? Some terribly made backend I'd assume. It's bad enough I gotta make a million accounts when applying to jobs but then you got my PII sitting behind such terrible password requirements it makes me wonder where else they are cutting corners on security.

you are viewing a single comment's thread
view the rest of the comments
[-] Fribbtastic@lemmy.world 15 points 18 hours ago* (last edited 16 hours ago)

Oh, let me tell you about Playstation that I had the pleasure of having to deal with it.

I needed to log in to my Playstation account but it told me that my username or password was wrong. Okay, send me a reset link. I got the link and set my new password.

I use Bitwarden and my password generator is set to 32 characters by default.

I generate a new password, paste that into the new password field, click okay and everything is fine, password changed. I save that new password in my vault and go back to the login site. I use the just changed credentials: Wrong username or password.

Well, turns out that the Password reset field is limited to 30 characters but the problem is that NOWHERE is it stated that your password has a max length. Not to mention that they don't tell you that your password was modified and cut short. The login password field, however, does allow more than 30 characters.

This means that you generate a 32-character password and paste that into the password reset field, this then gets cut short to 30 characters, click save and then use the same password on the login, which is 32 characters. This now obviously doesn't work because those passwords aren't the same.

Fun times. The worst part is that the first support person just went "Well, everything looks fine on our side. Sucks for you. Goodbye".

this post was submitted on 28 Nov 2024
57 points (96.7% liked)

cybersecurity

3306 readers
172 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 1 year ago
MODERATORS