‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. coaksford · · focus · HN ↗
    All my worst experiences with password length have been banking and finance and it boggles my mind that they all get something so incredibly basic so incredibly wrong. What is it about this sector that makes it so?
    1. kstrauser · · focus · HN ↗
      One of my most favorite things in the world was when an org with an outdated security program told me we&#x27;d have to rotate our passwords monthly. Then I&#x27;d get to tell them that no, we wouldn&#x27;t, and due to modern security practices, we couldn&#x27;t without causing a compliance exception.

      Sometimes I ended up explaining that to a well-meaning but overworked person who just wasn&#x27;t aware of the &quot;new&quot; (cough 2017) standard, but they&#x27;d ask me for the citation and giggle gleefully, thrilled that they could show their boss that they could knock off that obsolete ritual.

      Sometimes I ended up with someone a little smug, because they were at a megacorp and I wasn&#x27;t, and you&#x27;d see the momentary flicker of surprise and uncertainty as they started to wonder if maybe they&#x27;d missed something, something very important. I took an unreasonable amount of joy from those interactions.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.