4 ms·
I've no insight to PayPal. But MS Live aka Passport aka Microsoft Account has a 16 char, limited character set limitation. I spoke with people that worked on th
by MichaelGG 9y ago
I've no insight to PayPal. But MS Live aka Passport aka Microsoft Account has a 16 char, limited character set limitation. I spoke with people that worked on the system. Basically, sometime a long time ago, someone made some code that checked this. And over the years, many other parts of the pipeline ended up coding it and depending upon the same restriction. They're aware of it, but it's not a worthwhile time investment versus other work. People don't get hacked because of the limit, they get hacked via phishing, reuse, etc. Spending time testing, debugging, fixing old code across disparate systems with possibly different owners is a big cost. There's higher priority work to be done, even within security.
- tlb 9y agoOne would hope that plaintext passwords aren't fed through a long pipeline of legacy systems. As soon as it's hashed, which is the first thing you should do, length is no longer an issue.
- davidli 9y agoYes, but you might have other legacy systems that implemented the validation rules for passwords. Changing these rules would prevent people from logging into legacy systems if they signed up via a newer flow with fewer restrictions.
- Someone1234 9y agoMicrosoft have over five different places you can change a password (all of which conform to the same set of business rules). That's the issue, it isn't a pipeline issue, it is that Microsoft consolidated tons of different services under a Microsoft Account so have a ton of redundant ways of doing something. Microsoft Accounts/.Net Account/Passports, are a huge mess in general that Microsoft need to fix. Password length restrictions still may not go away even if they did (for backwards compatibility reasons with older software/hardware still around).
- teh_klev 9y agoOh don't get me started about this mess. I use Skype for the browser rather than any of the installable clients. There are days when it's simply not possible to login when you're redirected around that whole MS "live login" thing. Every other time I've logged into to a MS site (say my dev account for VS Community) some other login for something else run by MS breaks...then I have to go hunting down cookies to delete. I've wasted tens of hours of my life over the past few years on this crap.
- some_account 9y agoYou are aware that developers who don't use Microsoft are happier, healthier, more productive and have more skills on their cv's? I don't bother with them and it's a dream.
- reacweb 9y agoThat is the problem with limitations: they are hard to remove. I have the case where the character _ was invalid in project names. I have fixed the code to accept _ where it was invalid in first place. The problem is that other tools are now checking that project names do not contain _. How many tools in how many places? I do not know. The issue is not big enough to justify coordination of all the development teams to ensure that their code accept _ in project names. This limitation will probably never disappear.
- tinalumfoil 9y agoAs hard as limitations are to remove, adding limitations later on is even harder. As a commenter above pointed out, bcrypt doesn't handle passwords longer than a certain length. Imagine you were moving from a hash without limit to one with a 16-chatacter limit. You would quickly wish you weren't so lenient on what passwords you accepted. The point is forcing reasonable limitations on people isn't always a bad thing.
- heavenlyblue 9y agoI understand a limit of 1K characters for a password, but I will never understand a limit of 16.
- romwell 9y agoJust to illustrate, the "horse battery staple correct"[1] - type passwords won't fit into 16 characters - and I can type that faster than QuyigGiX_07~! - type nonsense that most websites require. Add to that the wonderful restrictions (oh, Citi doesn't like special characters that are too special, so QuyigGiX-07! it must be, etc), and you have a guarantee for frustration. I guess it all comes down to the fact that people aren't going to stop using a service because the password UX is horrible - especially given that it's nearly uniformly horrible elsewhere. [1]https://xkcd.com/936/ https://xkcd.com/936/
- dogma1138 9y ago
- stordoff 9y agoLive is definitely a bit of a mess. I changed my password a while back and, IIRC, included a '%'. Worked fine on PC/Xbox, but then I went back to a GFWL game some time later and found that it would claim my password was incorrect. Took me a while to work out -- I assumed it was just a bugged install because I could log in fine elsewhere, and a password reset didn't help -- but eventually realised that changing my password to something that didn't include that character let me log in.