I think you will find it shows an 8-character password for everybody. In
fact it cannot know how many characters there are in the clear text
password, because the encryption is one-way. When you type your password in
to be checked it encrypts it and checks against the encrypted version in

It would be possible to detect a one character password in /etc/shadow and
mark the account as disabled in the GUI, and maybe that would be a good
idea. On the other hand that is just a convention; there are many other
possible ways of disabling the password - just choose a string that can
never be the result of the encryption.

