DEV Community

Discussion on: RegEx password validators is madness

Collapse
 
subinsv profile image
subin sv

And some sites have max password length restriction, which is even dumber.

Collapse
 
pinotattari profile image
Riccardo Bernardini

Often those sites have also a set of "forbidden" characters, a really, really, really smelly practice... Most probably they store the passwords in plain text and process them as strings....

Collapse
 
polterguy profile image
Thomas Hansen AINIRO.IO • Edited

Probably a symptom of that they're not hashing their passwords, but storing them as varchar(25) in their database as plain text. I'd stay far away from such sites if I was you ... ;)