6 ms·
Similarly there are many sites that allow you to log in using `your password` or `your password`.swapcase() (for example, Password123 or pASSWORD123). Automatic
by qwerty1793 5y ago
Similarly there are many sites that allow you to log in using `your password` or `your password`.swapcase() (for example, Password123 or pASSWORD123). Automatically trying a variant only costs a single bit of entropy and can greatly reduce login issues
- jikbd 5y agoI remember this being the case on Facebook?
- egeozcan 5y agoIt was possible to login with the reverse of your password (as in password.split().reverse().join('')).
- piaste 5y agoWhat was the reasoning? Unlike case or typos, you wouldn't accidentally type a password backwards.
- deleted 5y ago[deleted]
- williamdclt 5y agoI could imagine having the left arrow key accidentally pressed (or stuck), but that's pretty niche
- input_sh 5y agoThis is in no way an educated guess, but it could be something about dealing with right-to-left language support?
- p49k 5y agoFor a long time, in some browsers/OSes there was a bug (or perhaps an archaic feature that was accidentally triggered) where the cursor in an input could get stuck and cause all new characters to be inserted to the left; I'm assuming it's related to that.
- Jenk 5y agoNotably this was a bug on the input for _setting_ your password, so if you think you've set Password123, you might have actually set 321drowassP, so even after fixing the bug it would still bite many users.
- Aachen 5y agoThis is the first I've heard of it, and as a Linux user I feel like it's the kind of thing I'd either know about or experienced first-hand. What kind of system would do that? And "for a long time", like, you can't ever login anywhere, it's kind of obvious and breaking functionality badly, how can this exist for more than a single release if at all?
- p49k 5y agoTo be clear, it’s intermittent. Perhaps one in 500 times an input is focused, it exhibits this behavior. I have experienced this so many times over my life with so many different hardware/software configurations, and I have to assume others have as well. It hasn’t happened in years but could explain why the “fix” described in the parent post was implemented.
- foepys 5y agoThis doesn't always work by the way. When you venture outside of ASCII, it's quite often uppercase(lowercase(x)) ≠ uppercase(x) and/or the other way around. The German letter ß gets uppercased to SS instead of ẞ by most libraries in a neutral/generic culture. ẞ on the other hand gets lowercased to ß. This happens because there wasn't an official ẞ in German until recently but the uppercasing/lowercasing standard was already written for ß.
- McMiniBurger 5y agobut don't password fields only recognize ascii? it seems i just can't type korean to password fields
- jeroenhd 5y agoMost competent websites I know accept general UTF8 characters like emoji perfectly fine. There are a lot of crappier websites that don't even have proper unicode support for usernames or profile descriptions out there, though, so your mileage may vary. As far as I know, there's nothing preventing a password field from containing any valid unicode string. The problem may be IME support or servers stuck in ASCII, but the textbox itself will just work.
- tsimionescu 5y agoEven surprisingly big names are surprisingly bad at this. Don't know recently, but Hotmail/Outlook used to have a rule of only using letters, numbers, and a handful of symbols, also limiting you to at most 16 characters or something. You couldn't even type a space!
- jeroenhd 5y agoHonestly, that stuff only proves that big name websites aren't necessarily competent. PayPal used to let you register an account with a password longer than the maximum password length used in the authentication code, for example, essentially allowing you to set a password you could never use with your account again. Being worth billions doesn't mean you've got all the basics down, it just means you've tricked many people into giving you their business. Even good websites that will accept any valid password string will sometimes cut off the last part of a long password because their hashing algorithm throws that data away. Bcrypt, for example, supports a maximum input length between 50 and 72 bytes, depending on the library you use to hash your passwords. That's bytes, not characters! More primitive systems used to have problems with non-alfanumerical passwords and once those algorithms have been unleashed upon the unsuspecting public, you need to support them in your login flow for years to come.
- darkhorn 5y agoThis is very English alphabet centric view. > only costs a single bit What if the password includes İ. The swapcase would be i. And the again its swapcase would be İ. And swapcase of I is ı. And swapcase of ı is I. Right? Well, it should depend on what language you use. Or should it? Also I think this was in Github; they ask uppercase and I enter Ğ and Github doesn't recognize it as uppercase letter.