- Feature Articles
- CodeSOD
- Error'd
-
Forums
-
Other Articles
- Random Article
- Other Series
- Alex's Soapbox
- Announcements
- Best of…
- Best of Email
- Best of the Sidebar
- Bring Your Own Code
- Coded Smorgasbord
- Mandatory Fun Day
- Off Topic
- Representative Line
- News Roundup
- Editor's Soapbox
- Software on the Rocks
- Souvenir Potpourri
- Sponsor Post
- Tales from the Interview
- The Daily WTF: Live
- Virtudyne
Admin
Matthew's Staples one is very common nowadays. You'll also find more and more sites won't accept a single or double quote (' or ") either.
I suspect Matthew is correct about the ampersand - but that suggests they're passing the password unencrypted to a web service.
The quotations marks one seems more to be an attempt to avoid some kind of SQL (or similar) injection, which again, implies that they're pushing around unencrypted passwords.
Edit Admin
You can't always fully hash on the client.
So maybe that they're not sure whether that's happening somewhere unknown deeper within their systems and want to be sure at every level.
Or maybe they've got a homebrew XML or JSON parser that might get confused with embedded quotes. Or they put the value into a querystring somewhere and are worried about url canonicalization errors.
If we hadn't built the web around everything being passed inter-machine and inter-language as strings with in-band signalling, we might have had some sanity. But noooo.