17 points

Nothing enrages me more than a password character limit. Thank you for making sure my password is LESS secure with your idiotic requirements based on security recommendations that are at least a decade old.

permalink
report
reply
5 points

How about… an undisclosed character limit? We’ll just keep telling you your password is invalid until you figure out the max length.

permalink
report
parent
reply
3 points

Let the users enter as many characters as they want and silently crop the password to a few characters.

permalink
report
parent
reply
2 points
Deleted by creator
permalink
report
parent
reply
3 points
*

Fun fact, this is a feature of Lemmy:

  • Lemmy has an undisclosed password limit of 60 characters.
  • Lemmy’s signup form will silently truncate passwords longer than 60 characters to 60 characters.
  • Lemmy’s login form will crash when passwords longer than 60 characters are submitted.

Someone please submit a PR

permalink
report
parent
reply
1 point

Just move to kbin.

permalink
report
parent
reply
2 points

I would give up before I figured that out and find some other service to use.

permalink
report
parent
reply
1 point

banks using EXACTLY 8 character passwords 💀 (srsly)

permalink
report
parent
reply
16 points

Try this simple and fun game to practice your password creation skills :^) https://neal.fun/password-game/

permalink
report
reply
2 points

Convince me this isn’t just training someone’s pet algorithm the same way we’ve all been trained to accept training the CAPTCHAs.

WAKE UP COMPILERS (It is a fun game though)

permalink
report
parent
reply
11 points

My bank requires your password to contain NO vowels. I always forget when I update the password (forced to every 3 months) and the error never mentions it.

permalink
report
reply
7 points

I’m struggling to think why this would be a thing. The only guess I have is someone was told to enforce “no dictionary words in a password” and saw that as an ‘easier’ way to implement?

permalink
report
parent
reply
5 points
*

One one hand it reduces the total # of characters needed to brute force which is bad. On the other hand, like you said, it makes it so dictionary attacks are weaker - which is good

Although I think you could just get a regular dictionary, remove the vowels, and it would probably work just fine

So ultimately? I think stupid decision

permalink
report
parent
reply
2 points
*
Deleted by creator
permalink
report
parent
reply
10 points
permalink
report
reply
7 points

I just use the KeePassXC password generator. :)

permalink
report
reply
4 points

Way too often I’ve had websites complain that the input password is too complex, and I have to dial down the settings.

permalink
report
parent
reply

Programmer Humor

!programmer_humor@programming.dev

Create post

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics

Community stats

  • 3.4K

    Monthly active users

  • 1K

    Posts

  • 38K

    Comments