Conversation
paypal silently truncated my 26-character password to 20 characters (but not in the login field, so I couldn't log in until I thought to look up the paypal password length limit and truncate it to 20 characters). why does that limit even exist? bcrypt has a much higher limit. I hate paypal
1
0
0
why are payment-related things always like this?

my bank requires an online banking PIN (separate from the ordinary one) and a password to log in, but instead of asking for the whole thing they ask for random access to individual characters. this both makes it inconvenient to use and implies they are storing them in plain text
1
1
0

@noisytoot Oh I think I encountered the very same issue with PayPal. It wasted lots of time trying to work out what was going on!

And re. asking for individual letters of the password, I know that at least one of the signatories to the UK's "Software Security Ambassadors Scheme" does this dubious practice...

0
0
1