‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. vegetablepotpie · · focus · HN ↗
    These are the same companies that state that users are responsible for choosing secure passwords… and then they make this as difficult as possible to do.

    Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.

    1. sippingabonedry · · focus · HN ↗
      &gt; they make this as difficult as possible to do.

      They provided password requirements which he ignored.

      &gt; Finance needs to be held accountable.

      Accountable for what, exactly?

      1. nemomarx · · focus · HN ↗
        if the requirements make it less secure, isn&#x27;t that the issue op is complaining about? max lengths are an anti feature.
        1. sippingabonedry · · focus · HN ↗
          Do you believe a 64-character password is magically more secure than a 20-character when they lockout your account after a few wrong tries? Delusion.
          1. yjftsjthsd-h · · focus · HN ↗
            If an attacker compromises the server and gets hashes, yes it could matter.
            1. sippingabonedry · · focus · HN ↗
              Sure give or take a few million years.

              A 20 character password is for all practical purposes mathematically immune to being brute forced.

              1. preg_match · · focus · HN ↗
                This assumes our computers basically just never evolve. Who knows what will happen in the next 10 years?

                And, this doesn’t even take into account dictionary attacks. You don’t need to brute force every character permutation a lot of the time, you just need to brute force words.

              2. danaris · · focus · HN ↗
                Except that

                a) when humans generate passwords, they are not perfectly random; they are memorable, which means they often use dictionary words, which are vulnerable to dictionary attacks

                b) even if they use moderately good passwords, that can&#x27;t be broken with the dictionary, there&#x27;s a high chance of password reuse, and many passwords have already been leaked

                c) when password managers generate truly random passwords, they run into exactly the problem in the article

                You are so focused on the math of the situation, you ignore the practical realities.

          2. altermetax · · focus · HN ↗
            Locking you out after a few wrong tries only protects against online attacks. If someone gets access to the database, they have as many attempts as they want.
            1. phatfish · · focus · HN ↗
              Brute force a strong 20 character password? Won&#x27;t the sun have burnt out by the time that is done?

              I use strong 12 character passwords at work, on the off chance i have to type them out. And as a favour to anyone else that might have to.

              1. altermetax · · focus · HN ↗
                Are there disadvantages in allowing users arbitrarily long passwords (or with a very high limit, e.g. 256 bytes)? No.

                Are there advantages? Yes: the longer the password is, the stronger it is. It doesn&#x27;t matter if there&#x27;s a specific point after which cracking takes time till the death of the universe. So there&#x27;s no point in imposing a limit.

                Besides, too many websites limit password length to ridiculous lengths like 12.

                1. sippingabonedry · · focus · HN ↗
                  You should reach out to the developers of all the major operating systems and explain how they&#x27;ve been doing it wrong all these years because they all set hard limits.
              2. xigoi · · focus · HN ↗
                For a 20-character password to be strong, you pretty much need to use random characters; you cannot use the superior “correct horse battery staple” approach as you’d be limited to two words, which isn’t very secure.
                1. phatfish · · focus · HN ↗
                  True, a pass phrase is a reasonable use of &quot;passwords&quot; &gt;20 characters.
          3. altruios · · focus · HN ↗
            &gt; 64-character password is magically more secure than a 20-character

            Not magic there, just information theory. but yes, I hear what you are trying to say. It is more cumbersome.

          4. Atheros · · focus · HN ↗
            Allowing extremely long passwords makes everything more secure because it teaches users to use better passwords.

            <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;936&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;936&#x2F;

      2. lapcat · · focus · HN ↗
        &gt; They provided password requirements which he ignored.

        No, you misunderstood what happened: &quot;Chrome inputs only abcdefghijklmnopqrstu (20 characters) as shown below&quot;

        1Password generated a password longer than 20 characters. When pasted, Chrome silently truncates the paste to the input maxlength!

        Look at the screenshot: The requirement &quot;Between 8 to 20 characters long&quot; has a green checkmark, because the requirement is satisfied.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.