‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. bootlooped · · focus · HN ↗
    My biggest question here is are they not just feeding the input into a hash function, why can&#x27;t it be longer than 20 characters?
    1. margalabargala · · focus · HN ↗
      Are you looking for the technical reason or the political one?
    2. zetanor · · focus · HN ↗
      It had to be restricted after someone started using a complete Wikipedia database dump as a password.
      1. Sohcahtoa82 · · focus · HN ↗
        If your web server isn&#x27;t throwing a 413 Content Too Large immediately after seeing a &quot;Content-length: 20000000000&quot; header, or bailing out after enough chunks from a &quot;Transfer-Encoding: chunked&quot; header, you configured it wrong.
        1. jagged-chisel · · focus · HN ↗
          But that upper limit has to indicated somewhere
    3. frenchtoast8 · · focus · HN ↗
      TFA says the mobile app works (so presumably the backend accepts long passwords fine). Looks like it&#x27;s just a frontend issue. I wonder if deleting the maxlength attribute before submitting the form works fine?
    4. coaksford · · focus · HN ↗
      At some point you don&#x27;t want people to enter the bee movie script, but where the word &quot;bee&quot; was replaced with the entire bee movie script again, recursively three times, all into the password field and tie up servers with extremely long requests.

      But 20 characters is simply ridiculous.

      1. shermantanktop · · focus · HN ↗
        &lt;input type=&quot;password&quot; maxbeemovierecursions=&quot;2&quot;&gt;
    5. arkadiyt · · focus · HN ↗
      bcrypt famously only looks at the first 72 bytes of the input. There are ways around that - don&#x27;t use bcrypt, or do bcrypt(sha256(password)), or whatever, but it is not the case that &quot;just feed the input to the hash&quot; removes all length restrictions
    6. hombre_fatal · · focus · HN ↗
      It&#x27;s a good habit to always create an upper bound on things (input max length, queue size, etc).

      The person who wrote it just came up with 20 in the moment and forgot to go check, something everyone has done a hundred times.

      I&#x27;ve probably never worked on a single system where the html validation, http server validation, and database constraint were synchronized on username max length. You choose a placeholder, an even number between 10 and 16, then forget to ever check.

    7. matja · · focus · HN ↗

          CREATE TABLE passwords (
            email VARCHAR(MAX),
            password VARCHAR(20) UNIQUE -- unique passwords are more secure.
              -- NOTE: &quot;20&quot; here because we used to use SHA1 hashes
              -- but there was an issue with storing binary in CP437
              -- so we just renamed the field.
          )
      1. kstrauser · · focus · HN ↗
        That just made me twitch so hard that I have a crick in my neck.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.