| Website | https://mossyvale.co.uk/ |
| Bluesky | @synx508.bsky.social |
| Website | https://mossyvale.co.uk/ |
| Bluesky | @synx508.bsky.social |
I looked up my own posting to the RISKS, I thought I had posted twice but maybe I didn't. Anyway, it made me a bit sad because the industry is so dumb and never really learns from mistakes. Thank you Peter G. Neumann, for at least trying to make people think about this stuff.
https://catless.ncl.ac.uk/Risks/21/54#subj4
Several years after posting this I was now married, living in a different town and our energy supplier decided to do the same thing, adding alphanumeric-only and length filters, locking us out of our own account with its properly secure password. But it's worse than that, before they added the filters you could set the password but attempts to use it resulted in a 500 error with ASP.net debug *turned on*, so we got to see some of the hideous SQL misdemeanour.