Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can. My wife, who I've taught to use a password manager, probably can't. And neither of these excuses a 27 character limit that strongly suggests my password is being stored unencrypted somewhere.


Not sure how that suggests that at all. User inputs have some sort of cap (don't want someone using a 2GB string as their password). So naturally there's a conversation at some point about "what's our maximum password size".

If that conversation starts off at 1000 characters you're fine, but more often then not it looks more like:

"Make the requirement 8-12 characters"

"12 is too short"

"fine make it longer, like"

"Ok" [18 char implementation]

"Hey, Bob in accounting says he uses 20 char passwords"

"Fine, bump it by another 50%"

[27 char implementation]

[no further internal complaints]

[Specs never updated or reviewed again]


It may well be encrypted, but not hashed...


use X windows - middle-click-to-paste usually gets around these 'no paste here' thingies. :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: