4 ms·
Slightly tangent to the random aside, but actively preventing the user from entering a bad password is very often bad because 99% of people implementing such a
by jdpage 12y ago
Slightly tangent to the random aside, but actively preventing the user from entering a bad password is very often bad because 99% of people implementing such a check have no idea what constitutes a good password, and the check actually enforces a bad one.
(Relevant xkcd: https://xkcd.com/936/ https://xkcd.com/936/)
I especially get mad at absurdly small (<200 chars) maximum lengths; a response of "but we require special characters" is bull. Increasing the size of the character space increases entropy by O(n^k) (polynomial); increasing the length increases entropy by O(k^n) (exponential). Anyone who's taken an undergrad algorithms course or even AP Comp Sci should understand this.
- Filligree 12y agoI'd comment on the rest of this, except... 200 chars? Really? Sure, there shouldn't be arbitrary limits, but... 200 chars?
- coderzach 12y agoI use the complete works of shakespeare as my passphrase. The rhyming makes it easy to remember. You just need to type deliberately as not to make a typo.
- logfromblammo 12y agoI actually used an entire paragraph from _Alice in Wonderland_ once. If I did it again, I might just make it Alice in Wasteland. How doth the little tronodile Improve his clanking tail, And pour the glowing hobo bile On every stainless scale! How cheerfully he seems to grin, How neatly spreads his claws, And welcomes desert rangers in With gently smiling jaws! Alas, your password must also contain a number, and it exceeds the maximum allowed length of 24 characters.
- lstamour 12y agoI think the idea was, if it's 200 characters as a limit, then it's not small. Anything less would be small, and closer to 0, absurdly small.
- swanson 12y agoPassword manager.
- ForHackernews 12y agoAll of my passwords are actually my last two tweets chained together. This 200 character limit is really screwing me.
- lurkinggrue 12y agoGiven it is hashing what you type I don't see a reason to limit it.
- DiThi 12y agoIs that a typo? I can consider <20 chars small, but not "absurdly" depending on what.
- jdpage 12y ago200 characters allows for the use of (short) passphrases. Longer would be better, though.
- dbbolton 12y agoI've brought this up before, but those passwords are more vulnerable to dictionary attacks: http://www.debianuserforums.org/viewtopic.php?p=11551&sid=148add51a26ba1a770278a8a4ff499f9#p11551 http://www.debianuserforums.org/viewtopic.php?p=11551&sid=14...
- EdwardDiego 12y agoSure, given an attacker having special knowledge.
- JoeAltmaier 12y ago...and "increasing the character set" actually means "reducing the password space". A rainbow algorithm for instance no longer has to test any plain words at all; just the ones with vowels replaced by digits and/or a special character added to the end. Its actually LESS entropy.
- ThrustVectoring 12y agoWhat really pisses me off (looking at you, Skype) is when adding text to a password makes it no longer valid. In other words, bvclkk27 passes validation, but bvclkk27skype doesn't. So. Frustrating. The second is strictly a stronger password than the first.
- lurkinggrue 12y agoIt's probably to stop people from doing hunter hunter2 hunter3 as passwords.
- spb 12y ago> I especially get mad at absurdly small (<200 chars) maximum lengths You realize even the well-regarded bcrypt algorithm only hashes 72 characters, right?
- jdpage 12y ago56, actually. It's a major shortcoming of bcrypt, and an argument in favour of algorithms like scrypt and PBKDF2. If you're committed to bcrypt, you could make an argument in favour of digesting the password with something like SHA384 first. That reduces entropy, but (a) it's strictly better than straight SHA, which is what a concerning number of people use already, and (b) it means that you're not messing up the user's pattern/mnemonic if they've got one going.