‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. bootlooped · · focus · HN ↗
    My biggest question here is are they not just feeding the input into a hash function, why can&#x27;t it be longer than 20 characters?
    1. zetanor · · focus · HN ↗
      It had to be restricted after someone started using a complete Wikipedia database dump as a password.
      1. Sohcahtoa82 · · focus · HN ↗
        If your web server isn&#x27;t throwing a 413 Content Too Large immediately after seeing a &quot;Content-length: 20000000000&quot; header, or bailing out after enough chunks from a &quot;Transfer-Encoding: chunked&quot; header, you configured it wrong.
        1. jagged-chisel · · focus · HN ↗
          But that upper limit has to indicated somewhere
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.