VideoLAN @videolan App Stores were a mistake. Currently, we cannot update VLC on Windows Store, and we cannot update VLC on Android Play Store, without reducing security or dropping a lot of users… For now, iOS App Store still allows us to ship for iOS9, but until when?

  • @gartheom
    link
    10
    edit-2
    9 months ago

    Setting a max password length is sometimes done to prevent ddos attacks. Without it, attackers could just spam 1MB passwords constantly and force the login server to just spend all its cpu time hashing garbage.

    That being said, a password limit of under 20 characters probably just means they are just storing passwords in plaintext.

    • I Cast Fist
      link
      fedilink
      29 months ago

      In Brazil, the govt owned lottery site, created around 2015, only accepts passwords with 6 numeric digits. Your password has to be a number between 000000 and 999999. Only somewhat recently (6 months ago or so) they’ve added a 2FA through an email link.

      Oh, said lottery is run by the biggest govt owned bank. Chances of people reusing their bank password there are very fucking high.