‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. bootlooped · · focus · HN ↗
    My biggest question here is are they not just feeding the input into a hash function, why can&#x27;t it be longer than 20 characters?
    1. matja · · focus · HN ↗

          CREATE TABLE passwords (
            email VARCHAR(MAX),
            password VARCHAR(20) UNIQUE -- unique passwords are more secure.
              -- NOTE: &quot;20&quot; here because we used to use SHA1 hashes
              -- but there was an issue with storing binary in CP437
              -- so we just renamed the field.
          )
      1. kstrauser · · focus · HN ↗
        That just made me twitch so hard that I have a crick in my neck.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.