Sunday, July 31, 2011

My Password is More Than 11 Characters

Dear WalMart,

Today I tried to make a purchase on your website.  As part of the purchasing process I set up an online account but got stuck when I had to enter my password and found out I can only use a password up to 11 characters.  Why is this?  Wouldn't it be better for the overall security of your site and your customers if customers used longer, more complicated passwords?  Sure I can see having a minimum number of characters; I can even see having a maximum number of characters, but 11?  Why not 50 or 100?  How about encouraging people to use pass-phrases rather than passwords?  Wouldn't this be even better?  More Secure?  Reduce your risk?

BTW, your not alone.  I have been on several other eCommerce sites that have this 11 character maximum.  I would like to suggest that all eCommerce sites that request a user registration end the limitations on lengths of passwords and find a better way of processing and storing them.

2 comments:

  1. Did you get a response? Their Devs are fans of Spinal Tap.

    ReplyDelete
  2. No response. I did receive my replica of Stonehenge today and it was much smaller than I imagined it to be!

    ReplyDelete