I just hate it when a program or website has a MAXIMUM password length, and despise even more when the password requirements/limits aren’t shown on the page. “Failed to update password” WHY!? WHY DID IT FAIL!? Oh, you think 16 characters is enough? Were my extra 70 bytes of storage space hurting your margins?
I use a password manager and I’ve twice seen a website not let me in with my saved credentials, and on resetting my account discovering that the maximum password length is now shorter than the password I have been using for months. If you are going to change the password constraints, fine, but you could allow login once and immediately force a password change.
I’ve seen it one step further. I can’t remember what the service was, but I signed up for it and copy pasted the password into my password manager, then tried to sign in with it. Couldn’t. Went back and forth with the “forgot my password” page about three times before I realized that not only was there a limit to the text length: you auto-truncated my input upon saving with no indication to me
I’ve run into that before too. The extra stupid part was the app was different than their website so the password worked on one but I had to drop some characters to use it on the other.
and despise even more when the password requirements/limits aren’t shown on the page
When they drip-feed you just one requirement at a time, only telling you one requirement that your chosen password doesn’t meet, and then they’ll tell you one more requirement that your next password doesn’t meet…
Correct me if I’m wrong, but if websites store your password in plain text, that’s already bad enough. As far as I’m aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense.
So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you’re using a terrible hashing algorithm). I don’t really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.
I appreciate your comment anyway! I didn’t know passwords would be hashed to a consistent length - I can see how that would be more secure.
I don’t think in the cases that I mentioned, that the hash of my entered/saved/extralong password was being compared to the stored hash they had on file, I think what happened is the input field validation was changed and would no longer allow a password that was valid under their previous rules.
I just hate it when a program or website has a MAXIMUM password length, and despise even more when the password requirements/limits aren’t shown on the page. “Failed to update password” WHY!? WHY DID IT FAIL!? Oh, you think 16 characters is enough? Were my extra 70 bytes of storage space hurting your margins?
I use a password manager and I’ve twice seen a website not let me in with my saved credentials, and on resetting my account discovering that the maximum password length is now shorter than the password I have been using for months. If you are going to change the password constraints, fine, but you could allow login once and immediately force a password change.
I’ve seen it one step further. I can’t remember what the service was, but I signed up for it and copy pasted the password into my password manager, then tried to sign in with it. Couldn’t. Went back and forth with the “forgot my password” page about three times before I realized that not only was there a limit to the text length: you auto-truncated my input upon saving with no indication to me
That’s so annoying!
I’ve also seen a login form where the username field also has the password type, so my password manager pastes the password in both!
I’ve run into that before too. The extra stupid part was the app was different than their website so the password worked on one but I had to drop some characters to use it on the other.
Believe it not, straight to jail.
When they drip-feed you just one requirement at a time, only telling you one requirement that your chosen password doesn’t meet, and then they’ll tell you one more requirement that your next password doesn’t meet…
Maybe don’t play this game…https://neal.fun/password-game/
Correct me if I’m wrong, but if websites store your password in plain text, that’s already bad enough. As far as I’m aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense. So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you’re using a terrible hashing algorithm). I don’t really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.
It’s somewhat common to limit password lengths to avoid DoS attacks that exploit a slow key generation function.
But that limitation should on some hundreds or a few thousands characters. Sites that use limits like “16” are probably storing them as plain text.
I appreciate your comment anyway! I didn’t know passwords would be hashed to a consistent length - I can see how that would be more secure.
I don’t think in the cases that I mentioned, that the hash of my entered/saved/extralong password was being compared to the stored hash they had on file, I think what happened is the input field validation was changed and would no longer allow a password that was valid under their previous rules.