Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Hotmail is also working hard to eliminate accounts that have simple passwords such as “12345678″ and “password” by increasing security measures and not allowing simple passwords to be created.

Awesome. Not like I use Hotmail, but... So now if someone's password generator just happen to generate "weak" password not containing, for example, a digit (uh, even `openssl rand -base64 12` provides such outputs from time to time) user'll have to step away from usual password generation scheme and create special password just for hotmail.com.

Please, for the love of sanity, never ever forbid any passwords (except for too short ones, with a reasonable minimal length). Just freak user out so he'll think twice before using possibly weak password. You'll educate users this way instead of frustrating them.

(And never limit maximum length or set of possible characters, except for rare cases where there are technical obstacles requiring to do so - like non-8-bit-safe protocols. If user wants to authenticate with a passpoem, written in runic alphabet — let him have it.)



Curious, what is your reasoning behind allowing 123456 in order to keep some kind of crazy "random generator" purity, but at the same time requiring a minimum length? Suppose my pw generator randomly generates passwords of different lengths? It seems to me the same operating principle behind why you don't want to limit character selection/order applies to string length as well.


I thought that a minimum limit's there just to ensure sanity of a generator. You can't generally predict how a hash function will behave, but you can certainly define a minimum output length. What I was thinking about, that the restrictions are too strict, and there's a gap between what's secure and what looks secure.

I believed that it's generally expected that a password generator would produce passwords of a certain minimal length. At least I considered that nobody would write a generator (intended for a real-world usage) that'd produce, say, 3-character password for some edge case.

However, you sound reasonable. This leads us right to the extreme case - should empty passwords be allowed? (Considering that the user will be bugged like hell before letting him to do so.)

I should think more about this.


I remember creating a blank password on Mac OS9 in grade school. It was clearly a bug that allowed me to do it, because the minimum password length was set to six characters, if I recall correctly. After I set the null password, I couldn't change it, but it worked fine for logging into my account. I was too embarrassed to ask the admin for help, so I was stuck with no password for about two years.


Yeah, seems silly. "It generated 111111, but I have to go with it because it's random."


One of my banks limits passwords to something like 12 characters. I called and asked why, their response was "because it's hard enough to remember 12 characters!".

sigh


My bank limits it to 6 characters being only uppercase letters and numbers.

:|


My bank says that too but it's really just 6 numbers because the characters map to the same numbers as on a telephone's key pad. So, if your password is ABC123, it's really just "222123", and both will work to log in.


My bank only allows passwords to be made of 5 numbers.

The interesting thing to note is that if they had any significant problem with this scheme, they would have changed it. Maybe we worry too much about the strength of passwords. The password verification process may be hardened enough, even for the needs of a bank.


What use is a password generation scheme if it manages to create one of the most used, and thereby one of the worst, passwords? Pure randomness surely must make way for generating something useful?


If your password generation scheme doesn't allow for arbitrary restrictions on the types of characters then I think it is already not a real great scheme.


Maybe a good way of freaking users out (and educating them at the same time) would be a notice saying "it will take n minutes/hours/millennia for someone to hack this password", rather than the "weak - strong" indicator you see on most sign up pages.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: