Hacker News new | ask | show | jobs
by entropic 4856 days ago
Some banks have IVR systems that allow users to log in to their account via telephone, so they only allow characters that can be entered via the touch-pad.

When you first create your password they translate the characters to the numerals on the phone and then hash it.

In my experience that is the most common reason why you'll see password for policies like: "Your password must be between 6 and 20 characters and only contain upper and lower case letters."