4 ms·
I only have one real complaint, and that is this: The email or password contains invalid invalid characters. Only letters (A-Z) and numbers (0-9) are a
by dannytatom 17y ago
I only have one real complaint, and that is this:
The email or password contains invalid invalid characters.
Only letters (A-Z) and numbers (0-9) are allowed.
What's the point in not allowing special characters in a password (serious question)?
- eru 17y agoGood question. Some banks (and other large companies) also seem to dislike them in passwords.
- pyre 17y agoSome stupid rule thought up by someone that is trying to force users to make passwords that they can remember. Like some sort of Web/IT version Clippy saying, "I see you're trying to enter a password with a '+' in it. Are you sure that isn't a typo?" Either that or their backend software is incompetent (as well as the people that made it) and can't handle pattern-matching outside of [:alnum:] or can't store character values outside of [:alnum:]. It's the same reason that there are many sites that you can't use the 'md5 a single password against the site's domain name' trick because they limit password length to 8 or 16 characters (as if they are some sort of 'accepted industry standard').
- durin42 17y agoI like that idea of using some sort of standard hash and password pairing along with the domain to come up with a password that's site-unique. Is that original, or taken from somewhere? Have you considered using base64 or some other encoding to shorten the string?
- janzer 17y agoI've used the extension from passwordmaker.org for quite some time. It implements this basic idea quite nicely.
- crux_ 17y agoBesides passwordmaker there's also the PwdHash firefox extension; I've been using that one for a while.
- pyre 17y agoMaybe I'm misunderstanding, but the string will already be Base64 if it's human readable (I'm not trying to use character 254 as part of my password) and base64 encoding actually grows the data you are encoding (since you are breaking some bytes down into two bytes to make them both human readable). The problem being length. Human-readable (ascii-armored/whatever) hashes (md5/sha-1/sha-256) have standard lengths which are usually longer than the maximum size of the password fields.
- durin42 17y agoI was assuming he was using the hex digest of the hash. You have to use some kind of ascii armoring, and base64 seemed like one that'd be reasonably safe.
- theycallmemorty 17y agoI think banks to alpha-numeric so you can type them in on the phone.
- munctional 17y agoIt reduces the keyspace that needs to be searched when bruteforcing... leading to accounts being compromised more easily. That's about it.
- Scriptor 17y agoAt the same time, I think it's just a really quick/lazy way to prevent SQL injection.
- lt 17y agoI hate when pages say my email is invalid because it has a plus sign in it.
- Tobias42 17y agoIs it even possible to enter any valid email address there? I have an email address whose only special character is the dot before the top level domain and it doesn't get accepted.
- Groxx 17y agoIgnore most of the other comments threading from this point, and HASH THE PASSWORDS with a salted hashing scheme. If it's not salted, it's almost as bad as not encrypting them at all. Hashed passwords are character-agnostic as well, so the only reason to limit your character-space then becomes preventing injection... which you should be using a library to do for you, because, frankly, "they" know better, and it's been more heavily tested than your code. If you're storing passwords in ANY reversible format, you're a threat to every user's security. It's part of why I like OpenID: if your server is compromised, I'm not.