‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. happyopossum · · focus · HN ↗
    &gt; Of course, my generated password is longer than 20 characters

    Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”?

    There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard.

    A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.

    1. raddan · · focus · HN ↗
      You are right about high entropy short-ish passwords but almost nobody does that. Virtually everybody chooses something not just low entropy but often easily crackable with good search heuristics. Why not give people another way to produce passwords that are harder to crack? With luck, at least a few people will choose a correct-horse-battery-staple.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.