Admin Passwords are Too Short!

posted by Cliff on 07:11 PM June 26th, 2000   Printer-friendly   Email story
jamesS writes "I noticed that when I change an author password, it only stores eight characters in the database. Or perhaps I entered the password wrong. :) So I changed the datatype of the pwd field in the author table to be type tinyblob. Now of course, I can't get at the original type of the password. Does anyone know what it was, and was it a good thing to change?"

Originally, author passwords where char(8) and this probably could do with some changing, I would think though that 20-30 char passwords would be more than sufficient. Note: Using BLOB datatypes for passwords is a bad idea since equality comparisons do not work and you won't be able to log in to your site, if you must change the password type, please stick with chars and varchars.

