9 ms·
This is years ago now, but every ampersand in my passwords came across wrong. I can't recall if it was missing or url encoded, but even passwords weren't safe.
by r1cka 4y ago
This is years ago now, but every ampersand in my passwords came across wrong. I can't recall if it was missing or url encoded, but even passwords weren't safe.
- xd1936 4y agoI'm still finding passwords in Bitwarden to old accounts that have `&` in them. Thanks, LastPass!
- userbinator 4y agoThat is especially surprising, considering that passwords are more than likely going to contain special characters.
- eru 4y agoLastPass's own generator puts them in there.
- fomine3 4y agoAvoid such trouble is why I want to avoid using symbols for password. Just use more alphanum characters for strength.
- xnickb 4y agoOr just use proper tools that work.
- r_c_a_d 4y agoI want to as well, but annoyingly there are many sites that insist on a "special" character because their strength measure says "low" for the 20 character alphanumeric string I generated %-}
- wonderwonder 4y agoMy favorite is when they actually limit what special characters you can use. Must include 1 of x special characters. Why? I always just assume they baked their own password storage and couldn't figure out how to handle the whole set of special characters
- jaywalk 4y agoMultiple times I've found that this is caused by a web application firewall that is intended to mitigate SQL injection attacks. So they disallow the characters that would commonly be used in those attacks.
- wonderwonder 4y agoInteresting, I had never considered that
- yencabulator 4y agoOn those sites, I generally insert the same fixed uppercase-and-symbol string on my zbase32ed-entropy passwords. Zbase32 tends to produce numbers already, and that combo tends to satisfy the silly sites.