fixed bug where we looked at the first byte of a password to determine