<input type="password" maxlength="20"> prevents me from logging into Vanguard
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
<input type="password" maxlength="20"> prevents me from logging into Vanguard
Unofficial Hacker News client; not affiliated with Y Combinator.
happyopossum · · focus · HN ↗
Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”?
There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard.
A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.
malfist · · focus · HN ↗
doubletwoyou · · focus · HN ↗
2. Stupid choices by services (like Vanguard!) making those extra characters a liability.
3. What are you protecting against? Even 16 characters with ~60 combinations is more than enough entropy.
4. It’s just cumbersome. And that, frankly, is the reason why the question is “why should you?”
tzs · · focus · HN ↗
The possibility of having to manually enter a password is actually why I used to want very long passwords to be allowed.
Say I have a streaming account, which I use from my desktop and maybe my phone or tablet. I never have to enter it manually on those devices because my password manager runs on all of them.
But then I want to use that service's streaming app on my TV. Nowadays most services have figured out a way for you to enter your credentials on their website or in the app on your phone or tablet and link that to your attempt to set it up on the TV, but back in the day most did not.
What we had to do back then is manually enter the password using the on-screen keyboard on the TV, navigated using the up/down/left/right buttons on the remote.
Worse, any time your password switched between symbols, numbers, lower case letters, and uppercase letters you needed to press some kind of shift key.
If long passwords were allowed I could pick a password that only uses say lower case letters from a small group that are right next to each other on the virtual keyboard, like qawe, and make up for the small character set with length. 40 random characters from qawe is 80 bits of entropy which is fine for a streaming account.