I don’t know why this is happening, but I can log in to my Facebook account even if I add just one random character either at the beginning or at the end of my password. For instance, I can log in if I type 1MYPASSWORD or MYPASSWORD1, where 1 is the additional random character I added.
This doesn’t happen when the cache and cookies are cleared (I get the classic wrong password error message).
Is this something to worry about? Does this happen to you as well?
Hashing multiple variations of your password every time you login will burn a couple of bits of entropy, but realistically if you're not using randomly generated passwords stored in a password manager you never had much security to begin with. They're just automating something that humans do manually