11 ms·
Except when you hit a website that refuses your auto-generated strong random password, which happens to me with shocking regularity.
by staticautomatic 6y ago
Except when you hit a website that refuses your auto-generated strong random password, which happens to me with shocking regularity.
- bigyikes 6y agoYour password must contain at least one special character. Except !, that isn’t allowed.
- tdrp 6y agoThe scariest one is when ' is not allowed.
- jniedrauer 6y agoMust include 1 special character, except for the following: ;`'"-
- tdrp 6y ago"Our client-side Javascript should be enough to prevent any SQL injection attempts" /s
- WrtCdEvrydy 6y agoMy favorite one is when it silently removes those characters but doesn't tell you...
- Bedon292 6y agoWorst think about 1password, and lastpass when I uses it, it doesn't let you pick what special characters it uses, despite it being such a common thing on websites. So you have to manually add them, or swap out thing.
- paulryanrogers 6y agoSurprising since Keepass has had that for years
- virtue3 6y agoI just add a random thing to the end of the password that fits the criteria
- smartbit 6y agoEnpass’ password generator has a field were you can enter characters not allowed. Regretfully Enpass doesn’t store this field nor the rest of the complexity rule as part of the password entry. The next time when password has to be changed you have to figure out the underlying complexity rule again.
- dddw 6y agoBitwarden let's you choose
- iso947 6y agoThe old “abchkkunenukzimejienejsidmdjiwknevgjk bgiknhhhnnisplwkslandhgabsndmskalpaapowhsoslxiaiapjsbsnsnaja” is not secure, but “P@55w0rd” is super duper secure.
- other_herbert 6y agoin our app we have a requirement that is similar.. I kicked and screamed and sent them spec documents from the NIST.. no one cared.. we have a max length of 10 chars... that SERIOUSLY hurts... 8 and 10 chars are our current requirements... plus some combination of numbers and special chars... WTFBBQ !!!!111... hypothetically it's "ok" but c'mon..
- yjftsjthsd-h 6y agoI mean, if you insist on a 10-char maximum, then mandating symbols to increase the search space is a good idea, right? (Granted, that doesn't make a 10-char max sane)
- tialaramex 6y agoAllowing symbols increases the search space, but requiring them reduces it. And in practice this effect can be exaggerated when people don't use random passwords but must actually choose a password they'll remember - because what they'll actually do is choose something easy and then shove a symbol in there to meet your requirement. You may well allow 30+ different symbols, or even more, but the users will invariably pick one of a dozen or so that were easiest to reach on their keyboard and they may learn to be shy of characters that sometimes "don't work" such as quote marks and any local currency symbol even if those are easy to type.
- ben_w 6y agoCould be worse. They might write it on a flipboard next to a window. https://grahamcluley.com/plymouth-passport-offices-pitiful-password-privacy/ https://grahamcluley.com/plymouth-passport-offices-pitiful-p...
- munkiefish 6y agohttps://youtu.be/aHaBH4LqGsI https://youtu.be/aHaBH4LqGsI
- waheoo 6y agoYou're not even seeing all the sites that truncate your password down to 6 characters. Hi Westpac.
- mooreds 6y agoThat's the worst, especially when the truncation is silent. Boo!
- RJIb8RBYxzAMX9u 6y agoThis is less annoying than sites that accepts your strong password, except their backend actually couldn't handle it. I love being locked out immediately on account creation.
- dddw 6y agoPassword!Drop!table
- mooreds 6y agoI've had that happen before, but even if you have to degrade your password, at least it is random and not associated with any other password/account. But yes, at that point all you can do is either complain to the website purveyor or vote with your feet (if the latter is an option).
- copperx 6y agoHow can you kick the server if you're not in the datacenter?
- gryfft 6y agoLittle enrages me more, especially when the forbidden special characters betray a shockingly backwards mitigation for injection attacks. [1] https://benhoyt.com/writings/dont-sanitize-do-escape/ https://benhoyt.com/writings/dont-sanitize-do-escape/
- JohnTHaller 6y agoMy favorite is when the website accepts your long random password but then the login fails. Because the set password function truncated the password before hashing it but the login function doesn't do that.
- OneLeggedCat 6y agoThis still happens, in 2020, with breathtaking regularity. Several times a year, a site won't accept my password, so I then start the whole "Will 20 characters work? No, that didn't work. Will 16? Nope... 15? Nope... 12? Nope. Oops I skipped 14... AH YES FINALLY."
- liability 6y agoThis will never change until engineers can be held criminally accountable for incompetence, particularly when personal information is involved. Of course any proposal to ever hold a programmer accountable for literally anything is always unpopular on HN, for obvious reasons.
- _t0du 6y agoBecause it's ridiculous to decide that the bottom of the decision graph should be held responsible for the poor decisions made from above. Engineers should only be held accountable for decisions they made personally. The unfortunate reality is that, a terrifying amount of the time, terrible decisions are handed to engineering teams as required implementation details from managers, executives, product directors, etc. So should engineers be held criminally accountable for their product manager demanding MD5 hashes on passwords?
- liability 6y agoAn engineer should be willing to tell his boss "No, because I would go to jail" If the manager insists anyway, the engineer should be obliged to refuse, even if that costs them their job. Of course management should also be held accountable, but until engineers are forced to have some skin in the game they will continue to be as pliable as wet noodles. Consider this: who better to blow the whistle on management than an engineer who knows they've been given an illegal order?
- Tainnor 6y agoMany password generators have options for such things though, like configurable length, character sets, etc.
- msla 6y agoIf a person ever even considers writing code which could generate either of these error messages: "Your password is too long!" "Your password uses special characters!" ... they are not only incompetent to write code which handles passwords, they have been so misinformed that they are an outright liability. They need to relearn everything they currently know on the subject and start over. Few things in the technical world instantly convey such utter anti-knowledge as the presence of either or both of those error messages in a codebase.
- IggleSniggle 6y agoIf that’s true, can you please share a link to your website so that I can stop using Dropbox and migrate my encoded data to be stored in your password field?
- Zecc 6y agoThey don't encrypt your password, they hash it.
- IggleSniggle 6y agoHrm, yes, good point. So my snarky comment loses its charm, if it ever had any. Still, though, I think it’s reasonable to alert the user if your password exceeds its allocated storage rather than silently truncate.
- gbear605 6y agoSome passwords are too long - I wouldn’t expect any website to accept a gigabyte long password - and I wouldn’t judge a site that doesn’t accepts \0 either.
- tdrp 6y agoI don't remember the math on hashing/bcrypt but isn't this the case that all passwords sort of hash to a fixed length string? Like why even have something like "your bank password must be 8-12 characters" long. Obviously for a gigabyte long it's a bandwidth and hash-computing issue :p
- helmsb 6y agoAlso, the chance that a site will refuse a strong random password is directly correlated to the importance of the account. Case and point, the appointment site for my barber happily takes a 30+ character randomly generated password. My old bank would not allow you to have a password longer than 12 characters and only recognized 4 special characters. That is why they are my old bank.
- greggman3 6y agoOr where their fancy SPA custom animated UX means your password manager can't auto insert a password.