Sunday, May 06, 2007

Slashdot | AOL's Embarassing Password Woes

An anonymous reader writes 'AOL.com users may think they have up to sixteen characters to use as a password, but they'd be wrong, thanks to this security artifact detailed by The Washington Post's Security Fix blog: 'Well, it turns out that when someone signs up for an AOL.com account, the user appears to be allowed to enter up to a 16-character password. AOL's system, however, doesn't read past the first eight characters.' This means that a user who uses 'password123' or any other obvious eight-character password with random numbers on the end is in effect using just that lame eight-character password.'"

No comments: