Worse than that must be the sudden realization that your bank probably saves your password in plain text somewhere.
hash($password) == $storedhash
hash(substr($password,0,20)) == $storedhash
Worse than that must be the sudden realization that your bank probably saves your password in plain text somewhere.