Live data from Hacker News

Why your password can’t have symbols—or be longer than 16 characters

arstechnica.com

71–75 of 75 posts

Re: Why your password can’t have symbols—or be longer than 16 characters

#71

It's not that they don't care, they are managing support headaches, and balancing risk to reward. 6 Character AlphaNumeric for Schwab is because they use the same password for phone, and this is a throwback to a "Pin". They could at least be honest that this is why it is what it is. The Fobs they send that generate a random number to go with your login make this not a deal breaker for me. Microsoft is balancing suppo…

Microsoft needs to buyout and then supply a stupidly simple, easy to use, password manager.

They need to test is against hoardes of naive users.

They need to encourage those users to have one long strong password to unlock the safe, and then to have strong random passwords for everything else.

Having seen how some computer users operate I guess any OS supplier has a hard job here. See, for example, the 'power users' who turned off UAC.

Re: Why your password can’t have symbols—or be longer than 16 characters

#72
post #65
post #56

Earlier quoted context omitted.

You do have a valid point. I used to have a password with a backtick (`) in it. That is a standard key on a QWERTY keyboard but seemingly untypeable on an iPhone. I didn't realize that until I actually tried to enter that password on my iPhone.

Here's how to do it: Hold down the apostrophe key until a menu pops up showing similar characters, then choose the backtick.

Or change your password using a computer, to a more iphone friendly password.

Re: Why your password can’t have symbols—or be longer than 16 characters

#73

I remember once reading a bank's FAQ trying to explain why passwords couldn't contain SELECT, UPDATE, DROP, or DELETE. I can't find it now so hopefully that little problem has been fixed...

No offensive words either! We don't want our engineers looking through our big plaintext files to get offended.

Our engineers have thick skin, they can handle it. However, we don't know how sensitive a potential hacker might be, and would feel terrible if we offended someone who wasn't expecting so see such profanity.

Re: Why your password can’t have symbols—or be longer than 16 characters

#74
post #70

Earlier quoted context omitted.

No offensive words either! We don't want our engineers looking through our big plaintext files to get offended.

I have various Google products under my account, which is my real name. One time I gave feedback to Google, from a Google feedback form, and gave my real (and had been in use for years) googlemail account name on this Google form. The form rejected it, because my real name has a mild swear in it. That kind of thing is vaguely disappointing. I did suddenly have to change all the answers to my 'secret questions' when I…

The solution is simple: change your name!

Re: Why your password can’t have symbols—or be longer than 16 characters

#75
I think Evernote's reason is actually surprising reasonable. I can imagine there's really some UIs that unreliably mess up leading and trailing spaces, and if they want to support those platforms, that means no leading and trailing spaces in the passwords. No spaces in the middle is too bad, you can disagree with their decision that "1.5 percent more entropy isn't worth the effort", but at least it's a reason, which is more than you can say about systems that limit their password length to 8 characters.

However, the real solution is that these password restrictions are in fact not restrictive enough: If everybody would require a password to be exactly 40 hexadecimal digits, no more and no less, this would force everybody to start using password managers, and they would all be much more secure.

Post reply on HN