5 ms·
The PayPal forgot password form had this bug just a couple years ago. I changed my password to a generated one. And it was too long. But it didn’t tell me. Just
by xahrepap 4y ago
The PayPal forgot password form had this bug just a couple years ago. I changed my password to a generated one. And it was too long. But it didn’t tell me. Just silently truncated.
I used the password reset to change it. This time I used a pretty short password I could type (to rule out a weird copy-paste bug or something). Logged in, went to the change password option and THAT page informed me there was a character limit.
- sshine 4y agoPassword character limits are important. They reveal that the back-end service probably doesn't hash the passwords, which is a good time to GTFO.
- Xylakant 4y agoI would consider setting a (high) limit for a password a good practice. No one wants an attacker to run a megabyte of password data through your slow password hash. It should be a limit that normal users never reach, but something like 100 chars seems entirely reasonable.
- BrandoElFollito 4y agoThe typical password managers allow you to generate up to ~120 characters, I would go for 500 just to be on the safe side.
- intuxikated 4y agoSome web frameworks have such limits built-in. Django for example has a limit of 4096 characters for password input, which should be more than enough for anyone, including people using long random-generated passwords from password managers
- afiori 4y agoThe reasonable thing to do is to prehash the user password on the client with a Unicode normalization and a SHA-512 pass. This way you can have strong input validation server side but also allow almost arbitrary inputs client side. PS: you likely could also salt the client side hashing and use bcrypt, but bcrypt has a quite short maximum length and I am not sure if it would provide significantly better security here.
- BrandoElFollito 4y agoMy bank requires a password of exactly 8 digits. In 2023.
- Haegin 4y agoA bank I used until about 2018 (no idea if they've fixed this yet - I left) had an exactly 6 character password, and when you used telephone banking it just needed the 6 digits that corresponded to that word. Those 6 numbers also worked online, so at best they were turning all passwords into numbers before hashing them, ensuring there are less than 900000 different possible passwords, which was trivially easy to brute force in 2015, nevermind today.
- BrandoElFollito 4y agoBruteforcing should not work as the attempts are either throttled, or lock the account. Provided that they are in place, otherwise the account is wide open. This i what happens with the 4 digits of a CC PIN and the 3 attempts before the card switches into PUK mode.
- WhyNotHugo 4y agoI know of banks which, in 2023, requires exactly 8 digits, the first four being numbers, the other four later letters. No digit can be repeated. Also no consecutive numbers. It's like they're deliberately trying to reduce the pool of valid inputs.
- BrandoElFollito 4y agoNot only this, but they also have a sadistic trait against their users. My password on another site (a bank too, IIRC) requires the password not to have my email username and consecutive, or repeated letters. My email username is "u" (as is u@example.com) and I usually generate a 50 or 70 characters long password. There is usually a "u" (they check the case, too). And come characters are repeated in the whole password. So I reduce the length, significantly, sometimes to 8 characters. The people who make rules in security in some areas are complete idiots.