Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Worse: I once set my E*Trade password to something it accepted but wouldn't recognize when I tried to log in… because it was too long.

After changing it I got locked out of my account and had to call support to resolve the issue. The worst part was that after verifying my identity over the phone they kept sending me reset links and I kept using long passwords generated by 1Password (30 characters IIRC) and it always accepted them when resetting but still would never let me log in.

It took many attempts and new reset links until they suggested trying a shorter password, which was eventually accepted both during reset AND login. Of course the reset page didn't mention a maximum length.



It gets worse: if you use 2fa the security code generated by the symantec thing is just appended to the password, so if your password is still a valid length, but then the 2fa takes it over 30 chars, it fails. It is the worst.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: