TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Does TransUnion really store passwords in plain text?

6 点作者 pfgallagher超过 3 年前
As I was attempting to log in to my TransUnion account today, I went to fill in my creds using my password manager. I received an interesting error message that stated passwords had to be between 8 and 15 characters. That caused me to raise my eyebrows since, as one might expect, my password-manager-generated password is longer than that and it has worked perfectly fine in the past.<p>On a hunch, I deleted the excess characters from my password. Lo and behold: I got right in. Unless I&#x27;m missing something, the only way they could have truncated it thusly would be if they&#x27;re storing it in plain text, right? Or, as my coworker just hypothesized, perhaps they were accepting longer passwords but only hashing up to 15 characters? Either way, seems fishy. Is anyone able to repro?<p>You&#x27;d think the credit bureaus would have invested in better security &#x2F; developers after the Equifax breach, but, perhaps not so unsurprisingly, it looks like they still have their heads in the sand.

1 comment

MattGaiser超过 3 年前
Why? What were the major downsides to Equifax?