<input type="password" maxlength="20"> prevents me from logging into Vanguard
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
<input type="password" maxlength="20"> prevents me from logging into Vanguard
Unofficial Hacker News client; not affiliated with Y Combinator.
vegetablepotpie · · focus · HN ↗
Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.
sippingabonedry · · focus · HN ↗
They provided password requirements which he ignored.
> Finance needs to be held accountable.
Accountable for what, exactly?
nemomarx · · focus · HN ↗
sippingabonedry · · focus · HN ↗
yjftsjthsd-h · · focus · HN ↗
sippingabonedry · · focus · HN ↗
A 20 character password is for all practical purposes mathematically immune to being brute forced.
preg_match · · focus · HN ↗
And, this doesn’t even take into account dictionary attacks. You don’t need to brute force every character permutation a lot of the time, you just need to brute force words.
danaris · · focus · HN ↗
a) when humans generate passwords, they are not perfectly random; they are memorable, which means they often use dictionary words, which are vulnerable to dictionary attacks
b) even if they use moderately good passwords, that can't be broken with the dictionary, there's a high chance of password reuse, and many passwords have already been leaked
c) when password managers generate truly random passwords, they run into exactly the problem in the article
You are so focused on the math of the situation, you ignore the practical realities.
altermetax · · focus · HN ↗
phatfish · · focus · HN ↗
I use strong 12 character passwords at work, on the off chance i have to type them out. And as a favour to anyone else that might have to.
altermetax · · focus · HN ↗
Are there advantages? Yes: the longer the password is, the stronger it is. It doesn't matter if there's a specific point after which cracking takes time till the death of the universe. So there's no point in imposing a limit.
Besides, too many websites limit password length to ridiculous lengths like 12.
sippingabonedry · · focus · HN ↗
xigoi · · focus · HN ↗
phatfish · · focus · HN ↗
altruios · · focus · HN ↗
Not magic there, just information theory. but yes, I hear what you are trying to say. It is more cumbersome.
Atheros · · focus · HN ↗
<a href="https://xkcd.com/936/" rel="nofollow">https://xkcd.com/936/
lapcat · · focus · HN ↗
No, you misunderstood what happened: "Chrome inputs only abcdefghijklmnopqrstu (20 characters) as shown below"
1Password generated a password longer than 20 characters. When pasted, Chrome silently truncates the paste to the input maxlength!
Look at the screenshot: The requirement "Between 8 to 20 characters long" has a green checkmark, because the requirement is satisfied.