‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. coaksford · · focus · HN ↗
    All my worst experiences with password length have been banking and finance and it boggles my mind that they all get something so incredibly basic so incredibly wrong. What is it about this sector that makes it so?
    1. sergiotapia · · focus · HN ↗
      Don&#x27;t get me started on passkeys, where it seems it was made for people who literally only use one device: their phone.

      Every time I prodded for a passkey I have to run a grep in my brain, what app did I use, or what it an extension, under my personal or work email?

      A NIGHTMARE, and for what.

      1. winkelmann · · focus · HN ↗
        At least let me actually use a security key! PayPal already lets you use security keys for 2FA, but it appears they only allow for smartphone based passkeys for some reason. I&#x27;m sure these are behind all the TPMs and Secure Enclaves and whatnot, but a security key is still orders of magnitude safer.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.