Here is the text of the NIST sp800-63b Digital Identity Guidelines.

  • einlander@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    Microsoft used to do that. I made a password in the late 90’s for a we service and I found out that it truncated my password when they made it after it warned my my password was too long when I tried to log in. It truncated at 16 characters.

    • catloaf@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      The weirdest one I found was a site that would only check to see if what you entered started with the correct password. So if your password was hunter2 and you tried hunter246, it would let you in.

      Which means not only were they storing the password, but they had to go out of their way to use the wrong kind of string comparison.