Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Customer service at banks tend to reply "for safety reasons" to any question you pose about their antiquated password limitations. A password limit of 20 characters? That's for safety reasons. Which safety reasons? We can't tell you, because of safety reasons.


> We can't tell you, because of safety reasons

Reminds me of another "security" organization.


Just so I know what bank(s) to avoid, which one is (or are) this?


ING in the Netherlands. Although to be fair, most banks have outrageously backwards password rules, and most limit the maximum length to something like 20 characters.


tl;dr: All of them.

Try it, ask your bank why they impose a limit of N characters for their passwords (I bet N is < 30 characters).

You'll almost certainly get a response along the lines of "We follow industry best practice" or something.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: