Hacker News new | ask | show | jobs
by swang 3704 days ago
because a lot of companies have no technical expertise at all.

american express use to enforce insane limits on passwords back in 2010[0]. 6-8 characters for passwords, no special character and had to have 1 letter, 1 number and it wasn't case sensitive. unfortunately _I_ had an amex card.

that page i linked to also has a reply from amex support who shows little knowledge about the difference between passwords and website encryption.

they eventually started expanding that limit from 6-8 characters to 8-20 characters around 2012? 2013?

[0] http://securitywatch.pcmag.com/e-commerce/284119-amex-passwo...