‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. vegetablepotpie · · focus · HN ↗
    These are the same companies that state that users are responsible for choosing secure passwords… and then they make this as difficult as possible to do.

    Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.

    1. sippingabonedry · · focus · HN ↗
      &gt; they make this as difficult as possible to do.

      They provided password requirements which he ignored.

      &gt; Finance needs to be held accountable.

      Accountable for what, exactly?

      1. nemomarx · · focus · HN ↗
        if the requirements make it less secure, isn&#x27;t that the issue op is complaining about? max lengths are an anti feature.
        1. sippingabonedry · · focus · HN ↗
          Do you believe a 64-character password is magically more secure than a 20-character when they lockout your account after a few wrong tries? Delusion.
          1. yjftsjthsd-h · · focus · HN ↗
            If an attacker compromises the server and gets hashes, yes it could matter.
            1. sippingabonedry · · focus · HN ↗
              Sure give or take a few million years.

              A 20 character password is for all practical purposes mathematically immune to being brute forced.

              1. preg_match · · focus · HN ↗
                This assumes our computers basically just never evolve. Who knows what will happen in the next 10 years?

                And, this doesn’t even take into account dictionary attacks. You don’t need to brute force every character permutation a lot of the time, you just need to brute force words.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.