Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As a long-time Schwab user, one thing I was shocked by is that the login flow silently truncates the password to eight characters. I found this since I tend to have complex suffixes I rotate around, and one day I was able to login with the wrong suffix and even with no suffix at all. This must be due to some legacy process only allowing eight characters.


Grounds for class action litigation?

To anyone looking to test this, once login again becomes possible: Response I've gotten from Schwab website to a wrong password is merely loading of a blank page, with an endless spinner on top.


That's surprising and alarming. Thank you for bringing that up, though!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: