‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. happyopossum · · focus · HN ↗
    &gt; Of course, my generated password is longer than 20 characters

    Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”?

    There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard.

    A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.

    1. raddan · · focus · HN ↗
      You are right about high entropy short-ish passwords but almost nobody does that. Virtually everybody chooses something not just low entropy but often easily crackable with good search heuristics. Why not give people another way to produce passwords that are harder to crack? With luck, at least a few people will choose a correct-horse-battery-staple.
    2. clickety_clack · · focus · HN ↗
      <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;936&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;936&#x2F;
      1. tanin · · focus · HN ↗
        My 1password actually generates 4 random words with symbols and numbers as delimiters. A generated password is often ~24 characters.
    3. malfist · · focus · HN ↗
      It costs me nothing to use a 20+ character password. The questions isn&#x27;t why should you, the question should be &quot;why shouldn&#x27;t you?&quot;
      1. doubletwoyou · · focus · HN ↗
        1. For whatever reason, and a reason will come, typing out those extra characters will be an extra pain.

        2. Stupid choices by services (like Vanguard!) making those extra characters a liability.

        3. What are you protecting against? Even 16 characters with ~60 combinations is more than enough entropy.

        4. It’s just cumbersome. And that, frankly, is the reason why the question is “why should you?”

        1. tzs · · focus · HN ↗
          &gt; For whatever reason, and a reason will come, typing out those extra characters will be an extra pain.

          The possibility of having to manually enter a password is actually why I used to want very long passwords to be allowed.

          Say I have a streaming account, which I use from my desktop and maybe my phone or tablet. I never have to enter it manually on those devices because my password manager runs on all of them.

          But then I want to use that service&#x27;s streaming app on my TV. Nowadays most services have figured out a way for you to enter your credentials on their website or in the app on your phone or tablet and link that to your attempt to set it up on the TV, but back in the day most did not.

          What we had to do back then is manually enter the password using the on-screen keyboard on the TV, navigated using the up&#x2F;down&#x2F;left&#x2F;right buttons on the remote.

          Worse, any time your password switched between symbols, numbers, lower case letters, and uppercase letters you needed to press some kind of shift key.

          If long passwords were allowed I could pick a password that only uses say lower case letters from a small group that are right next to each other on the virtual keyboard, like qawe, and make up for the small character set with length. 40 random characters from qawe is 80 bits of entropy which is fine for a streaming account.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.