Can somebody with a FB account verify this?
The implications of this are staggering.
Facebook automatically weakens your passwords?
@0x56 well....the plot thickens.
Using a different laptop, on a different network I did these tests in this order:
1) valid pwd prefaced with extra char=fail
2) valid pwd chars but all upper case=fail
3) valid pwd with extra char appended to end= success
Now...
All upper case continues to fail every time
Prefaced extra char sporadically works
Appended extra char always works.
I'm out of time now to test more now but will see what I can do later.