a previous bank used to have a max password length of 8 characters, then proudly announced that they will increase it to 32
Then I made a typo at the end of my password and it let me in anyway, and I realised they were just trimming the first 8 characters to give the illusion of security
I tried then first N characters of my password until I found out the threshold was at 8, then I tried with the first 8 chartacters of my password and then random junk and it worked.
I also had two friends in the same bank to validate