<input type="password" maxlength="20"> prevents me from logging into Vanguard
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
<input type="password" maxlength="20"> prevents me from logging into Vanguard
Unofficial Hacker News client; not affiliated with Y Combinator.
flufluflufluffy · · focus · HN ↗
While I acknowledge your issue is incredibly frustrating, it is still good practice to use the maxlength attribute. Yes, it can be bypassed. Yes, you should still check the length on the backend. But it’s one more layer of ensuring sanitary input. Obviously, companies should do a better job of communicating the maximum password length to the user, properly setting the attributes on all inputs, AND if they do enforce a max length, having it be large enough that it ensures a secure password, but we shouldn’t just abandon using the HTML attribute altogether.
yallpendantools · · focus · HN ↗
I think statement from TFA basically boils down to "stop enforcing maxlengths on passwords, neither in the form field nor the DB". I'm no security expert but I'm a `correct horse battery staple`-adherent so if anything, password fields should have a minimum length, not maximum. Short passwords should be what's considered dirty.
flufluflufluffy · · focus · HN ↗
For example, a password value of a million characters, to me, would be unsanitary, or unexpected. Of course it’s possible somebody might want to use that as their password, but more likely it’s an attempt at a buffer overflow. I’m not saying there is a specific number where it changes from sanitary to unsanitary, but choosing some reasonable value to limit the length at would be a good idea. Even outside of security, from a purely utilitarian perspective, it would make sense to have some limit on the length of any data you’re storing/processing.
Re: security, yes, there should be a reasonable minimum length as well.
Atheros · · focus · HN ↗