Hacker News new | past | comments | ask | show | jobs | submit login

For perspective, this is an absurdly short sequence.



You could argue that there should be no limit or maybe the limit should be higher, but I'd have a hard time arguing that a 10 character password composed of upper, lower, specials and digits is absurd


You _should_ argue that there ought to be no limit. There is absolutely no reason why there should be a limit below maybe 4k (and even then, I'm not sure. Perhaps some limit if DOS is concern...).

The only reason why there are limits now is that there is code running on their servers specifically stopping passwords that are longer - which is insane, if you think about it - they are actively preventing people from creating stronger passwords. I'd rather create a 20-30 character password with no specials (which is still massively harder to crack than a 10 char with all possible specials), because it is easier to type in on mobile, but with this system, I couldn't - which is dumb.


They don't accept lower case - if you have capslock on you'll still be logged in. I don't think they accept all special characters either.


Ouch. I didn't know their passwords were case insensitive.

I thought they didn't accept all special characters either, but I just successfully changed my password with special characters that I don't remember them accepting last time I changed my password. I was successfully able to log in using a version of my new password with the case changed for some letters.


You're right - I just tried my password using all caps instead of mixed-case - ouch!




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: