<input type="password" maxlength="20"> prevents me from logging into Vanguard
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
<input type="password" maxlength="20"> prevents me from logging into Vanguard
Unofficial Hacker News client; not affiliated with Y Combinator.
40four · · focus · HN ↗
I guess I don’t really understand the reasons any engineering team would limit password length, but at least implement in a way that is apparent to the user. Successfully saving a password that is different than the user expects is wild.
Moreover, in the case of a financial institution like Vanguard, limiting password length feels particularly offensive.
efilife · · focus · HN ↗
The bcrypt hashing algorithm doesn't work on inputs above ~60* characters or so. It will just silently trim your input. Better to do it yourself
*72 bytes
40four · · focus · HN ↗