‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. flufluflufluffy · · focus · HN ↗
    &gt; This is one example why we shouldn&#x27;t use the maxlength attribute on the password field.

    While I acknowledge your issue is incredibly frustrating, it is still good practice to use the maxlength attribute. Yes, it can be bypassed. Yes, you should still check the length on the backend. But it’s one more layer of ensuring sanitary input. Obviously, companies should do a better job of communicating the maximum password length to the user, properly setting the attributes on all inputs, AND if they do enforce a max length, having it be large enough that it ensures a secure password, but we shouldn’t just abandon using the HTML attribute altogether.

    1. yallpendantools · · focus · HN ↗
      Can you elaborate how this sanitizes input on a password field? What unsanitary password input does it prevent?

      I think statement from TFA basically boils down to &quot;stop enforcing maxlengths on passwords, neither in the form field nor the DB&quot;. I&#x27;m no security expert but I&#x27;m a `correct horse battery staple`-adherent so if anything, password fields should have a minimum length, not maximum. Short passwords should be what&#x27;s considered dirty.

      1. flufluflufluffy · · focus · HN ↗
        I meant sanitary in a general sense. Maybe a better word would be “unexpected.” You want to minimize the possibility of receiving unexpected input. Though not perfect, the maxlength attribute is one way of getting there.

        For example, a password value of a million characters, to me, would be unsanitary, or unexpected. Of course it’s possible somebody might want to use that as their password, but more likely it’s an attempt at a buffer overflow. I’m not saying there is a specific number where it changes from sanitary to unsanitary, but choosing some reasonable value to limit the length at would be a good idea. Even outside of security, from a purely utilitarian perspective, it would make sense to have some limit on the length of any data you’re storing&#x2F;processing.

        Re: security, yes, there should be a reasonable minimum length as well.

        1. Atheros · · focus · HN ↗
          Servers usually accept data in a thousand ways in a thousand endpoints. Anyone who tries to prevent buffer overflow or slowloris attacks by limiting password length specifically is doing it wrong. An absurdly long password is surely one of the least likely places where a resource-use vulnerability would pop up since the data usually gets sent straight into a 20 year old hash implementation.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.