‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. 40four · · focus · HN ↗
    I’ve ran into this same issue numerous times on different platforms. They silently enforce a max length, unannounced to you, then you can’t log in later until you figure out the correct length.

    I guess I don’t really understand the reasons any engineering team would limit password length, but at least implement in a way that is apparent to the user. Successfully saving a password that is different than the user expects is wild.

    Moreover, in the case of a financial institution like Vanguard, limiting password length feels particularly offensive.

    1. efilife · · focus · HN ↗
      &gt; I guess I don’t really understand the reasons any engineering team would limit password length

      The bcrypt hashing algorithm doesn&#x27;t work on inputs above ~60* characters or so. It will just silently trim your input. Better to do it yourself

      *72 bytes

      1. Atheros · · focus · HN ↗
        In case any programmers read this, the better procedure, if you want to use bcrypt, is to hash the password with something else first, like SHA512, then feed the output into bcrypt.
        1. efilife · · focus · HN ↗
          what&#x27;s the point in using bcrypt then? I researched this years ago and nothing ever convinced me it&#x27;s not redundant
          1. Atheros · · focus · HN ↗
            to slow down attackers who want to brute force your password hash. At least that was the idea. I guess it also includes the salt stuff built in so that it&#x27;s harder for implementers to screw up.

            Is a 9-order-of-magnitude slow down worth the trouble? I dunno. Maybe.

      2. 40four · · focus · HN ↗
        Interesting, I didn’t know that. My knowledge of cryptography is admittedly not great. 20 characters limit is pretty aggressive though.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.