‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. 40four · · focus · HN ↗
    I’ve ran into this same issue numerous times on different platforms. They silently enforce a max length, unannounced to you, then you can’t log in later until you figure out the correct length.

    I guess I don’t really understand the reasons any engineering team would limit password length, but at least implement in a way that is apparent to the user. Successfully saving a password that is different than the user expects is wild.

    Moreover, in the case of a financial institution like Vanguard, limiting password length feels particularly offensive.

    1. efilife · · focus · HN ↗
      &gt; I guess I don’t really understand the reasons any engineering team would limit password length

      The bcrypt hashing algorithm doesn&#x27;t work on inputs above ~60* characters or so. It will just silently trim your input. Better to do it yourself

      *72 bytes

      1. 40four · · focus · HN ↗
        Interesting, I didn’t know that. My knowledge of cryptography is admittedly not great. 20 characters limit is pretty aggressive though.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.