Last week, I tried to register for a service and was really surprised by a password limit of 16 characters. Why on earth yould you impose such strict limits? Never heard of correct horse battery staple?

  • Lycist@lemmy.world
    link
    fedilink
    arrow-up
    39
    ·
    9 months ago

    Its even better when they don’t tell you that your password is too long, and they truncate it somewhere unknown.

    Tried a randomgen 32 character password at the local sheriff’s office. Copy and pasted it directly out of my password manager into the password creation field so I know I didn’t typo it and when I tried to login it wouldn’t work. Took me a bit of troubleshooting to figure out what happened.

      • Zorsith@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        6
        ·
        9 months ago

        Ive seen an account creation or password reset that let’s you do any length password, but the actual login page has a character limit.

    • Midnight Wolf@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      9 months ago

      That happens all the fucking time, and it’s infuriating. Most recent example was with Kagi, which I eventually found out had a max of 72, truncated, no warning. I bitched out their support and they were like ‘nbd, and it should have warned you’ and I’m like ‘nope, no warning at all’ which means they didn’t bother checking if a warning actually showed or prevented the input, just ‘I wrote it so we must be good’.

      They claim to have fixed this, but ugh. Took me a half an hour, and I started with the suspicion that it was being truncated. Test your shit if you’re going to be stupid, people.

      • frezik@midwest.social
        link
        fedilink
        arrow-up
        1
        ·
        9 months ago

        Bcrypt and scrypt have a limit of 72 chars, so it’s probably that. Implementations can work around it by putting the password through a pre-hash, but most don’t bother. There are tons of reasonably secure password storage systems with that limit.