‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. nly · · focus · HN ↗
    My hot take is that almost nobody should be setting _any_ length or complexity requirements on passwords. Instead just enforce the need for at least some kind of second factor, even if it&#x27;s SMS, TOTP or a magic link by email.

    If your password hash database is compromised you&#x27;re screwed anyway, because dictionary attacks scale horizontally, even with slow hashes designed for passwords &#x27;LickMyLiver123!!&#x27; isn&#x27;t necessarily going to hold up just because it&#x27;s 16 characters.

    The average vocabulary of a 20 year old native English speaker is perhaps ~50,000 words and I bet when you apply some basic grammar rules, and pragmatic search paths like relying on tonnes of people just smashing !&#x27;s on the end of their usual password when a minimum length is enforced, those hashes start to fall quickly.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.