SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Non-Tech : Datek Brokerage $9.95 a trade -- Ignore unavailable to you. Want to Upgrade?


To: David Kuspa who wrote (7207)3/5/1998 8:46:00 PM
From: Spots  Respond to of 16892
 
I'm working from memory as to exact length, but my password
is over ten characters long. When I enter it to logon or
submit and order, it is accepted in full. When I enter it
to update email address (for instance), which I did recently,
it was rejected till I limited it to 10 or 9 or something.

I wouldn't be at all surprised if the server verifies only
the first xxx chars of the password. This isn't considered
a security violation for security certification.

I also remember reading somewhere on the site the password
limit but I chose (emphasis, CHOSE) to enter a longer one
so I could remember it better.

It's better security to accept more characters at the end
of a password without comment, even if they aren't checked,
than to reject it. Carried to the extreme (if you need
convincing), a password checker might say "Password invalid:
you missed the 3rd and 7th position by one and the 1st
was in the wrong case ...". This is way out, but I've
seen responses that weren't all that far off from this.

Regards