Skip to content

Comment on American Express fails miserably at basic securityparent

Comments

From a previous HN thread, here's the real reason at least for AmEx: http://news.ycombinator.com/item?id=1108650

There are ways around legacy systems not storing certain characters to database field sizes that range from running delegate password serves to hashing passwords into something that an be stored on the legacy system. The one thing this thread does get at is the money involved. To Amex the costs and risks of their "weak" password requirements don't outweigh those of implementing a more secure password system.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.