Hacker News new | past | comments | ask | show | jobs | submit login

> I've never had a website outright reject certain special characters,

This is exceedingly common for US Banks. You'll find, usually only after pasting in the newly generated random password and clicking submit, that the "your password must include at least one number and two special characters" description up front failed to also include: "oh, also, we do not allow use of the character % in your password" (or some other character).




When I created an account to take out a mortgage with a UK bank, I found they allowed up to 12 ASCII alphanumeric chars for a password. I forget if there was a min length.

This was around October 2019, so it's not like they shouldn't have know better.


It's even worse for UK banks, which ask you to (for example) "enter the 4th, 5th and 11th character of your password."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: