3 ms·
My favorite is when it must have punctuation, but certain punctuation is silently banned, so I have to keep refreshing my password generator until it gives me a
by InitialLastName 8mo ago
My favorite is when it must have punctuation, but certain punctuation is silently banned, so I have to keep refreshing my password generator until it gives me an acceptable combination.
- abustamam 8mo agoSomewhat unrelated, is there any technical reason certain punctuation might be banned? I can understand maybe not allowing letters with diacritics or other NON-ASCII chars but why would a system reject an @ sign or bracket > for example?
- GoblinSlayer 8mo agoDepending on the protocol they can be url encoded or even helpfully html encoded; the same password can be used over different protocols. It's the best to not use punctuation by default (length supplies more entropy than charset), I add -0 at the end to make dumb password policies happy.
- InitialLastName 8mo agoOften, the same ones with limited punctuation also have length limits, so maximizing the character options is the only way to maximize entropy.
- abustamam 8mo agoThis is true, but I think the argument is that for maintainers of the system, it's more work to allow more char options when it (should be) more trivial to change MAX_PASS_LENGTH from 12 to 32. Like, if you're gonna add more restrictions, make it the ones that encourage, not block, more secure passwords.
- abustamam 8mo agoSorry I'm a bit lost here. Are you saying requiring a special character and a number are dumb password policies? Wouldn't charset AND length make for exponentially higher entropy? 52 (or 62 for digits) to the length power vs (62+20 special chars) to the length power? Or am I missing something?
- ajnin 8mo agoI guess what they're saying is that, for example, a password of length 12 has about 71 bits of entropy if using an alphabet of 62 characters, and 76 bits with an alphabet of 82 characters. But if you only increase the length by 1 you already get 77 bits with 62 characters only. So length beats adding special chars in that sense.
- abustamam 8mo agoGotcha, I guess my question is, why not both? Is it the requirement of special chars over a min-length password that is in question here? Like the system is like "minimum 8 char password but also three special chars, ancient heiroglyphs, and the blood of your firstborn child" when you can omit the special chars and just have min 16 char password for the same security benefit?
- GoblinSlayer 8mo agoNot very meaningful to create yourself a problem to heroically overcome it later. You can already create enough problems unintentionally.
- abustamam 8mo agoI don't quite follow your reasoning. All bugs are (usually) unintentional and created by the programmer.
- pintxo 8mo agoBy not using special chars in the first place, you can be sure you will not be able to run into any (unintentional) bugs later. And not using special chars is cheap, as by requiring a min-length of 13 instead of 12, you can get an even greater level of security.
- angst_ridden 8mo agoA lot of the restricted stuff is cargo-cult fear of symbols that could be used in SQL-injection or XSS attacks. A properly-coded system wouldn't care, but the people who write the rules have read old OWASP documents and in there they saw these symbols were somehow involved in big scary hacks that they didn't understand. So it's easier to ban them.
- korhojoa 8mo agoI came across a "special character" requirement while creating an account. The client validation was not the same as the server validation. The client proceeded as if my account was created, but it never was. The client functioned without an account until it was closed. I asked the creator what their app's problem was, why did I need to keep resetting my password, then be told that I don't have an account, and have to create it anew. They would not believe I was creating an account and using the device, because their own logging was so terrible. I had to send them a screen recording from me using this abomination, and only then was I told "you're using the wrong special characters". They helpfully gave me some examples of allowed special characters, which then would pass the server validation. I wish they would have gotten rid of the account requirement, as the device and client software seemed to work fine without them.
- __MatrixMan__ 8mo agoSometimes when that happens, and any of `:({ |&;` are on the no-no list, I try bypassing the client validations and setting my password to a shell fork bomb. So far as I'm aware it hasn't broken anything yet, but I'm determined to keep trying.