6 ms·
Is noisily deleting passwords acceptable in your eyes? (i.e. "Your password contains spaces, which is disallowed by our policy. Please try again.")
by beobab 7y ago
Is noisily deleting passwords acceptable in your eyes?
(i.e. "Your password contains spaces, which is disallowed by our policy. Please try again.")
- rossng 7y agoIt's annoying in either case. Passwords should be any string I want! You're just going to hash it anyway. I found it particularly egregious that Zoom's form auto-trims any spaces from the end of the string - so they are deleted as you type with no feedback (unless you happen to be watching the dots flicker).
- iguy 7y agoDoes it matter? I mean is there another way of entering this string which preserves the spaces, or is deleting them just part of the hash function?
- rossng 7y agoYes, you can paste a string with internal spaces. I guess you can also disable JS and type whatever you want. Passwords with spaces work absolutely fine, too - it's just the signup form that is broken.
- Faark 7y agoThey probably had to many people accidentally copy-pasting strings with spaces into the form. Like the good old "double click to select a word" also picking up the space after the word. The reason I can empathize with your complain is it being highly unlikely they are able to keep those restrictions consistent across all password forms & login methods.
- z3t4 7y agoI remember when I started out with SQL databases, someone managed to hack the site using SQL injects. So I made a SQL sanitation function, but soon enough someone complained that they couln't have escape characters in their password. =) Now a days I always use a library that parameterize all SQL variables to avoid SQL injections.
- rhinoceraptor 7y ago> You're just going to hash it anyway Wow, you're optimistic :)