4 ms·
I attempted to sign up with a 50 character 1Password-generated password, and was told that passwords cannot be longer than 20 characters. I can't see any reaso
by gorena 11y ago
I attempted to sign up with a 50 character 1Password-generated password, and was told that passwords cannot be longer than 20 characters.
I can't see any reason for this other than that they're storing them either encrypted or in cleartext.
Use with caution.
- murbard2 11y agoOr they just have length bounds on every string input that they have (as they should) but the person in charge of deciding the bound for the passwords did a bad job and picked too low of a limit.
- atonse 11y agoNormally I'd cry foul but 20 alphanumeric characters (roughly 64^20, or 1e36 combinations) is more than sufficient.
- chaz72 11y agoThe issue is not the 20 characters, but the underlying reason for it. There's no technical reason they would need it unless they were storing it insecurely. Granted it's possible they're limiting it to 20 for a nontechnical reason, but I have some 40-character passwords in a password manager. Long passwords are not only reasonable, but this is a giant alarm bell if they even imply they might be storing them insecurely.
- nicpottier 11y agoWhat are you talking about? Taken to its logical conclusion you would have sites support passwords up to a million characters or else it is a sign that they are insecure. Having some limit is perfectly sane. I also find it a bit "armchair quarterbacky" to be calling out PayPal on security practices. They've been around the block a few times, and though I certainly don't love them, they aren't making rookie mistakes like not-hashing passwords or the like. You are just spreading FUD for no discernable reason. 20 characters while not the epitome of greatness, isn't a sign of the end times.
- pidg 11y ago"armchair quarterbacky" would make quite a good password, but unfortunately it's 1 character over their limit.
- ascagnel_ 11y agoTheoretically speaking, shouldn't a solid salt + hash algorithm always result in a fixed-length string no matter the input password?
- atonse 11y agoIt should, but I think parent is talking about the input string having a limitation, which limits the amount of combinations you could have in your password. My original comment still stands, though, as 20 characters is a large amount of combinations (although I just did some quick calculations to find it's still less than 128 bits... 114 or so).
- jsmeaton 11y agoYou can DOS a site that doesn't have password length enforcement. 20 characters really is too low though, because it rules out a lot of pass phrases. I believe Django allows up to 4mb for the password, which is more than enough for any sane password.
- minimaxir 11y ago> I can't see any reason for this other than that they're storing them either encrypted or in cleartext. One of the (bad) reasons companies impose password length limits is that the user is less likely to forger a shorter password, and therefore it saves money on inevitable support calls. Granted, a 20-character limit is probably too high for this justification to be valid.
- andrewmcwatters 11y agoWow, thanks for the heads up! Yeah, I mean like I only use websites that allow me to use 2048 character passwords, because I like to use lorem ipsum websites as my password generators.
- cptskippy 11y ago> I can't see any reason for this other than that they're storing them either encrypted or in cleartext. I can't see any reason for this conclusion other than the fact that you've never worked for a large corporation where product development often dictated by departments other than IT.