* Posts by rebelcode

1 publicly visible post • joined 13 Sep 2018

Solid password practice on Capital One's site? Don't bank on it

rebelcode

British Gas and E-bay do this too

British Gas allow you to paste a new password in but to confirm it you have to type it in. An email discussion with them confirm that's by design too. Ebay also don't allow pasting of passwords when setting your password, and email conversation with them shows that's deliberate as well.

I know that it's not exactly the same subject but there are also websites that have really stupid password policies. The most immediate one that comes to mind is Lambeth Council where a password now must be no longer than 8 characters, whereas about 4 years ago you could have up to 16 characters. Email conversations with them over the years shows a worrying lack of understanding abotu password security. On the plus side you can paste passwords