6 ms·
Or sites that require at least one symbol, but then mysteriously disallow a handful of common symbols (e.g. I used a site the other day where exclamation points
by ReidZB 9y ago
Or sites that require at least one symbol, but then mysteriously disallow a handful of common symbols (e.g. I used a site the other day where exclamation points were not allowed). Makes password generators like 1Password's useless about half the time, since 1Password rightly will pick from all (most?) common symbols on a standard US keyboard.
And of course, why would the site tell the user of its obscure symbol requirements before the user tries to enter their brand new password? No, I guess they think it's better to leave it at "a symbol is required" and then reject symbols users use one-by-one.
- generj 9y agoMaybe password rules should be represented as an HTML5 attribute in the input field. 1Password and LastPass et. al. could read this rule and then adjust the password generator accordingly.
- tass 9y agoWhat reasons are there for these restrictions in the first place?
- generj 9y agoThe length requirements are logical if they have reasonable minimums and very high maximums. It doesn't make sense to limit special characters, etc. Especially as everyone should be using a password manager anyways. I suspect most of these odd requirements are a result of design by committee and pointy haired bosses. Maybe requirements from legal departments? As long as the annoying requirements are in place, we might as well try and get password mangers to work with them. LastPass has a generator which can be manually configured, but making the step automated would be helpful.
- majewsky 9y ago> very high maximums What does "very high" mean here? And why would you need it? Usually, you just have a maximum request size in the web server, and people are never going to hit that with actual passwords.
- ReidZB 9y agoAlgorithms like bcrypt may have a maximum supported length: for bcrypt, over about 50 characters and things get dicey [1]. If you're running something computationally expensive like scrypt tuned properly, you don't want malicious entities to be able to send you a 32K password request, probably - easier to force them to keep it small (like < 50 chars), then block them based on request throughput. [1] https://security.stackexchange.com/a/39851/1373 https://security.stackexchange.com/a/39851/1373
- ma2rten 9y agoThe only problem with that is that websites that have obscure password rules don't tend to be ones adopting modern HTML5 tags.
- JumpCrisscross 9y ago> Makes password generators like 1Password's useless about half the time I just generate a long alphanumeric password and then manually throw in a few symbols.
- xaedes 9y ago"Your password is too long." "How much? Figure it out by yourself!"
- fooker 9y agoAh, must be a fan of binary search!
- davchana 9y agoFew sites silently use the first n characters and discard the rest, without any error. You find it only when u try to login. India's pension system (kind of similar to 401k, you contribute monthly, you get pension monthly after 60) (eNPS (national pension system))[https://cra-nsdl.com/CRA/ https://cra-nsdl.com/CRA/] does this. At initial signup, it helpfully tells max length is 14 chars. You need to change password every 3 months. So, i added a 1 behind keepass generated password. It said success. Error at login. Somehow i tried with earlier password. It went in, but said change password as its 3months old.
- petre 9y agoOr disallows UTF8 characters.
- BlackFly 9y agoYour average developer considering allowing UTF-8 is going to weigh the cost benefits of unicode normalization vs. just forcing the user to use the lower ASCII code page and is going to opt for the lower ASCII code page. If you are randomly generating the password anyways, I'm pretty sure allowing full UTF-8 will decrease the entropy since there are more wasted bits. I could be wrong, and I am too lazy to run the computation at the moment. Moreover, a randomly generated UTF-8 password will almost certainly contain characters that are difficult for the user to type.
- tzs 9y agoI'd guess that this might be an attempt (perhaps misguided) to prevent people from using characters that they won't be able to type on some devices. For example, on Mac I can easily enter Unicode from the keyboard by enabling hex unicode input (at least for Unicode up to U+FFFF...have to use surrogates to get past the BMP). On my Windows desktop there is a similar option, with one annoying limitation: it requires using the numeric keypad. That's fine on my desktop system. It has a keyboard with a numeric keypad. It sucks on my Surface Pro 4. Both the real and the virtual keyboards there lack a numeric keypad. There are other options for Unicode on the SP4, but they are quite annoying. If the site is an audio or video streaming site or a social media site or a photo sharing site then they might also be worried about people who will want to use them from their TV, A/V receiver, cable box, DVR, or Blu-ray player, all of which nowadays often provide network access and apps for various media services and social media sites. I don't think any of mine have a way to enter arbitrary Unicode from their clunky on-screen keyboards. Speaking of TVs, cable boxes, etc., I wish sites would think more about those when setting password requirements. It is often cumbersome and slow to switch between lower case and upper case, or between letters and punctuation, or between alpha and numeric when using an onscreen keyboard via a remote control when all you've got is up/down/right/left for navigation. I'd rather use a 21 character password using [a-z] or a 29 character password using [0-9] than use a 16 character password using, say, [a-zA-Z0-9!@#$%^&+:;]. Best, though, is to make it so you don't need to enter passwords on these devices to pair them with your services. I don't remember which service it was but I've seen one that handled it something like this. 1. You go to the website for their service and log in. On the website you can tell it you want to enable your account for their app on your device, and you give the device model and serial number. The website gives you a temporary PIN. 2. You go to the device and tell their app you want to enable your account. The app asks for the PIN then talks to the web service. The app and the web service can then set up everything for you.
- RJIb8RBYxzAMX9u 9y agoPassword Safe[0] allows you to define a custom symbols list, for each entry. Not that this particular feature is worth switching over for, but just want to point out that it's not a limitation for all password managers. [0] https://pwsafe.org/ https://pwsafe.org/