‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. happyopossum · · focus · HN ↗
    &gt; Of course, my generated password is longer than 20 characters

    Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”?

    There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard.

    A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.

    1. clickety_clack · · focus · HN ↗
      <a href="https:&#x2F;&#x2F;xkcd.com&#x2F;936&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkcd.com&#x2F;936&#x2F;
      1. tanin · · focus · HN ↗
        My 1password actually generates 4 random words with symbols and numbers as delimiters. A generated password is often ~24 characters.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.