• spechter@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Another favorite of mine is truncating the password to a certain length w/o informing the user.

    • NotationalSymmetry@ani.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Saving the password truncates but validation doesn’t. So it just fails every time you try to log in with no explanation. The number of times I have seen this in a production website is too damn high.