3 ms·
I signed up and used a 30-character secure (alpha+symbols) password. The signup accepted the password, but now I'm unable to sign in, and the password reset isn
by dhess 16y ago
I signed up and used a 30-character secure (alpha+symbols) password. The signup accepted the password, but now I'm unable to sign in, and the password reset isn't working. Help? My tagmask account name is dhess, and my contact info is in my profile.
- vietor 16y agoIs there a common library that's being used which causes this behavior? I've encountered it elsewhere, and it's amazingly annoying. Nothing says fun like having to reset your password 4 times in a row because the website is silently modifying it.
- dotBen 16y agoA common design pattern flaw is only hashing the first x characters of the password and storing the result during sign up but then hashing the entire password on log in which results in a miss-match during authentication. If you use long passwords try removing the last character and seeing if you can still log in to your favorite website - on many you probably can.
- vietor 16y agoYeah, I'm aware the problem was truncation, it just took me a few tries to figure it out. My making a typo seemed much more probable than something that stupid being true. In practice, what sort of process do you think would cause someone to implement this mistake? It seems obviously dumb to truncate something that you're hashing anyway. (To truncate it to something human relevant anyway, rather than like 512 characters). That's why I asked if it was in some bugged library, it seems bizarre that the same totally boneheaded design would be recreated independently. It's not just that it truncates it, it's that it does it differently.
- GrooveStomp 16y agoI encountered this issue with LinkedIn. With LinkedIn, they restricted the password length to something like 20 characters, but accept an input of arbitrary size. There's a disconnect afterward based on the string they store vs the string that's generated when you re-enter the too-long password. Maybe they do a server-side encryption on initial creation, but subsequent logins use a client-side encryption? I'm not sure. EDIT: I'm trying to sign up with a 20-character password consisting of uppercase and lowercase letters, and numbers, but I keep getting this error (which has a typo): "Username can contains only letters, numbers and underscores."
- pankratiev 16y agoThis error means that something is wrong with the username. Note that you can use only lowercase characters in username. I agree that there is unclear error message, I'll fix it.
- GrooveStomp 16y agoThanks for the info. Yeah, it's confusing. On the Username input I was also getting the error, but the example shows: http://tagmask.com/yourName http://tagmask.com/yourName Which has camel case that's invalid. :)
- pankratiev 16y agoI've sent to you an email.