• Darren (unregistered)

    Matthew's Staples one is very common nowadays. You'll also find more and more sites won't accept a single or double quote (' or ") either.

    I suspect Matthew is correct about the ampersand - but that suggests they're passing the password unencrypted to a web service.

    The quotations marks one seems more to be an attempt to avoid some kind of SQL (or similar) injection, which again, implies that they're pushing around unencrypted passwords.

  • (nodebb)

    You can't always fully hash on the client.

    So maybe that they're not sure whether that's happening somewhere unknown deeper within their systems and want to be sure at every level.

    Or maybe they've got a homebrew XML or JSON parser that might get confused with embedded quotes. Or they put the value into a querystring somewhere and are worried about url canonicalization errors.

    If we hadn't built the web around everything being passed inter-machine and inter-language as strings with in-band signalling, we might have had some sanity. But noooo.

  • RLB (unregistered)
    Comment held for moderation.

Leave a comment on “12345”

Log In or post as a guest

Replying to comment #705011:

« Return to Article