Skip to content

Comment on AmEx: "We discourage the use of special characters because..."parent

Comments

This doesn't make sense to me. Any "legacy" systems involved surely pre-date online account access by consumers. They would not have ANY password field or even any notion of a "user" in the sense of someone who is able to access a specific account.

This would have all been built as a web application talking to the backend through a CICS gateway of some sort. The web app would be responsible for authenticating the user, not the legacy mainframe system.

They probably keep the password in an 8-char record that used to store something else.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.