But 20 characters is simply ridiculous.
The person who wrote it just came up with 20 in the moment and forgot to go check, something everyone has done a hundred times.
I've probably never worked on a single system where the html validation, http server validation, and database constraint were synchronized on username max length. You choose a placeholder, an even number between 10 and 16, then forget to ever check.
CREATE TABLE passwords (
email VARCHAR(MAX),
password VARCHAR(20) UNIQUE -- unique passwords are more secure.
-- NOTE: "20" here because we used to use SHA1 hashes
-- but there was an issue with storing binary in CP437
-- so we just renamed the field.
)Ass covering instead of responsibility.
Security theatre, in other words.
When the consequences for failure are very high but personal reward for success is very low, everyone does everything they can to avoid being held responsible for the consequences.
Note that I didn’t write “avoid consequences”!
That’s different.
It baffles me why so many sites block paste on bank account number inputs like it is 1995 and we are typing it from checks.
I could log into the website just fine, but the app kept saying my password was wrong. I reset my password, and when I was generating a new password, I found the root cause:
At some point, they changed the password policy to have a maximum length of 16 characters. My existing 20 character password worked fine in the website which didn't actually enforce a 20-character limit in the password field, but the app was silently truncating the last 4 characters when BitWarden was filling in the field.
Limiting password length to only 16 characters scares me. It makes me think they're not hashing passwords in the back end.
Its probably for the best.
Allegedly the new website is coming https://investor.vanguard.com/new-vanguard-experience
It's way better than doing anything with computershare.
Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.
They provided password requirements which he ignored.
> Finance needs to be held accountable.
Accountable for what, exactly?
Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”?
There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard.
A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.
And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: https://www.reddit.com/r/PersonalFinanceCanada/comments/4t0m...
For the Americans who might not be aware of what BMO is (it's not some podunk small town bank): https://en.wikipedia.org/wiki/Bank_of_Montreal
I agree that it any system that allows this IS almost certainly just storing as plain text, and that it’s bad regardless.
so I figured that the way to make it work is to have it autofill, then select my username and press space then backspace, which is a no-op. That way, the javascript knows i've entered something, and then it works.
While I acknowledge your issue is incredibly frustrating, it is still good practice to use the maxlength attribute. Yes, it can be bypassed. Yes, you should still check the length on the backend. But it’s one more layer of ensuring sanitary input. Obviously, companies should do a better job of communicating the maximum password length to the user, properly setting the attributes on all inputs, AND if they do enforce a max length, having it be large enough that it ensures a secure password, but we shouldn’t just abandon using the HTML attribute altogether.
I think statement from TFA basically boils down to "stop enforcing maxlengths on passwords, neither in the form field nor the DB". I'm no security expert but I'm a `correct horse battery staple`-adherent so if anything, password fields should have a minimum length, not maximum. Short passwords should be what's considered dirty.
If your password hash database is compromised you're screwed anyway, because dictionary attacks scale horizontally, even with slow hashes designed for passwords 'LickMyLiver123!!' isn't necessarily going to hold up just because it's 16 characters.
The average vocabulary of a 20 year old native English speaker is perhaps ~50,000 words and I bet when you apply some basic grammar rules, and pragmatic search paths like relying on tonnes of people just smashing !'s on the end of their usual password when a minimum length is enforced, those hashes start to fall quickly.
This is the real problem. They let him set a password they did not accept.
Also, for finance specifically : " A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional way along with his fellows, so that no one can really blame him." - Keynes
Every time I prodded for a passkey I have to run a grep in my brain, what app did I use, or what it an extension, under my personal or work email?
A NIGHTMARE, and for what.
I think they use some cursed (or secure I guess) combo of stringent special character requirements, no reuse of old passwords, and automatic resets after incorrect guesses.
It actually hasn’t been an issue after finally using a password manager, but I remember it being a regular headache before that.
Sometimes I ended up explaining that to a well-meaning but overworked person who just wasn't aware of the "new" (cough 2017) standard, but they'd ask me for the citation and giggle gleefully, thrilled that they could show their boss that they could knock off that obsolete ritual.
Sometimes I ended up with someone a little smug, because they were at a megacorp and I wasn't, and you'd see the momentary flicker of surprise and uncertainty as they started to wonder if maybe they'd missed something, something very important. I took an unreasonable amount of joy from those interactions.
I think it has to do with the fact that Banks are heavily driven by nation law and regulation, so it's not engineering folk that are at the helm, rather it's driven by natural language source code written by non technical people that compiles to target code through engineering lackeys. It works for the most part, but you get very weird failure modes.
A 20 character password is for all practical purposes mathematically immune to being brute forced.
I use strong 12 character passwords at work, on the off chance i have to type them out. And as a favour to anyone else that might have to.
Not magic there, just information theory. but yes, I hear what you are trying to say. It is more cumbersome.
No, you misunderstood what happened: "Chrome inputs only abcdefghijklmnopqrstu (20 characters) as shown below"
1Password generated a password longer than 20 characters. When pasted, Chrome silently truncates the paste to the input maxlength!
Look at the screenshot: The requirement "Between 8 to 20 characters long" has a green checkmark, because the requirement is satisfied.
Maybe news hasn't traveled north and broadcast on the CBC, so maybe you haven't heard, but BMO has branches all over the US.
Additionally First Citizens acquired a bunch of "BMO" branchs and is presumably converting them back to their branding.
https://www.google.com/search?client=firefox-b-d&q=first+cit...
fnord77•1h ago
gustavus•47m ago