<input type="password" maxlength="20"> prevents me from logging into Vanguard
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
<input type="password" maxlength="20"> prevents me from logging into Vanguard
Unofficial Hacker News client; not affiliated with Y Combinator.
happyopossum · · focus · HN ↗
Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”?
There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard.
A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.
clickety_clack · · focus · HN ↗
tanin · · focus · HN ↗