Strange Redbox Password Policy

Maximum of 12 characters for passwords on redbox.com

Another site with odd password policies, redbox.com. Requiring a minimum password length is a good idea, though you could argue that six is too small. But why limit the maximum password length to 12 characters? Any site that has a maximum password restriction below 50 characters has me wondering how exactly they are managing password storage and security.

3 thoughts on “Strange Redbox Password Policy

  1. Joseph

    I just sent an email to Scott at Redbox (their API lead) to have him look at your post and address this as it will certainly be a growing concern for the tech community.

    Thanks for being on top of these things!

  2. Good catch! I’ve had services tell me storage is an issue here before which sends me running as, well, that’s what hashes are for….

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>