I think the worst case ive seen is a 16 character limit, not enforced at sign up, but enforced at login
Comment on No, you can't keep your 20 year old dictionary password
Grostleton@lemmy.dbzer0.com 2 days ago
I’d happily use a passphrase with multiple unrelated 8-12 character words but for some reason most businesses have upper limits on how many characters can be used…
district@lemmy.zip 1 day ago
rekabis@lemmy.ca 1 day ago
This was Microsoft - for their online services such as Hotmail or Outlook.com or Azure - well into the 21st century. They first lifted that limit in 1999, then re-established that in 2012. They only re-reversed it back to a longer option (up to 256 characters) in 2019.
Like, morons.
JustAnotherKay@lemmy.world 20 hours ago
I’ve seen this, fucking brutal UX lol
rekabis@lemmy.ca 1 day ago
And more and more businesses are also limiting what characters you use.
Like, my random generator uses characters from the entire European UTF-8 printable character set. This expands the number of usable characters from about 68-74 (the typical uppercase, lowercase, 0-9 & special characters) to about 1,200 characters. This includes all Latin, Cyrillic, and Greek variations used across Europe.
Just using the wider UTF-8 range nearly always doubles the bitwise complexity (as KeePass measures it) if not more, thereby dramatically reducing the ability for the password to be brute-forced. Not to mention using characters that are not expected to be in passwords in the first place - most brute forcing simply doesn’t account for that where a primarily English-speaking victim set is concerned.
Plus, the passwords are not short. I usually prefer 32 characters, and in important/mission-critical services I expand it to 64 characters.
mercano@lemmy.world 2 days ago
Some sites require special characters in their passwords, other websites don’t even allow them. I use a password manager, but still have to tweak the password generation rule for some sites.
arrow74@lemmy.zip 2 days ago
Sure, but it’s going on a sticky note taped on the bottom of my keyboard
SirEDCaLot@lemmy.today 1 day ago
Look at you with the heavy security. No need for that, right on the monitor should be fine. In fact to avoid confusion you should write ‘Computer PW: correcthorsebatterystaple’ so you don’t forget what the note is there for.
Thrawn@lemmy.dbzer0.com 2 days ago
Oh there has to be an upper limit for things like buffer overflow or just plain RAM capacity limits. But even with allowing the max possible range of characters you are still looking at something like 100,000 in a single 1mb size and I’m sure they could manage to do that and still pass it along to a high quality hashing function.
If you try putting in a password longer than that yes reject it.
asdfasdfasdf@lemmy.world 1 day ago
That is dumb bit what’s even dumber is disabling paste.
snooggums@piefed.world 2 days ago
That is the character limit on the database field where they store your password in plain text.
Carl@anarchist.nexus 2 days ago
Yup.
For the unaware: modern hash algorithms have character limits, but it’s nothing that would ever interfere with a regular password. Even accounting for the salt that gets appended to the end of your password before it goes into the algorithm. Most of the popular hashes have a 128 character limit, and the site will also store a salt in your user’s database entry. That salt gets appended to your password before it goes into the hash. Basically, even if two users have the same password, the hash for each will see “password{Salt1}” and “password{Salt2}”. So they won’t show as the same hash in the database, even though they’re the same password.
This salt is to prevent something called a rainbow table attack, where a hacker feeds a bunch of common passwords into a bunch of common hash algorithms, then compares with their stolen database. If they find matches, they now know which algorithm the database was using, and they only need to brute force the database once. So for instance, they feed “{common password}” into several hashing algorithms. One gives the result “1234567890”. They then check their stolen database, and find several users with the hash “1234567890”. They try using {common password} on those user accounts, and they work! Now the hacker knows which hash algorithm was used, and can brute force the entire stolen database at their leisure.
By appending a salt to each password, “{common password}” actually becomes “{common password}{Salt1}” “{common password}{Salt2}”, etc… So even if the hacker tries to brute force it, they would need to brute force each individual password instead of brute forcing the entire database all at once. It’s still important to use strong passwords, because a weak password will still be broken in only a few seconds. But that will be a few seconds per weak password, instead of a few seconds for every user at the same time. This is why sites tell you to change your password after a breach. The idea is that salting the database makes brute force attacks take a lot longer, and gives most users time to change their passwords before the attackers manage to get anything.
All of this is to say, you could have a 100 character password limit, and still have plenty of room for a 16-28 character salt. And the hashes will output the same length string regardless of what you feed into it. So longer or shorter passwords won’t matter, because they’ll all turn into a 64 character hash in the end.
So putting a low character limit on a password is a site admin tattling on themselves, because it means they’re not hashing your password at all. If they were hashing it, the only upper limit on your password would be whatever the algorithm can accept (probably 128 characters) minus 20-30 characters for a salt.
safesyrup@feddit.org 2 days ago
Almost every hash algorithm does not have a character limit and instead uses chaining. Bcrypt is the odd one out of using only the first 72 bytes of a supplied password, tough you can still supply a longer password even if it does not make a difference.
AceFuzzLord@lemmy.zip 1 day ago
Despite salting passwords, I would personally also like to see a lower character limit, to get people into the habit, combined with said salting. Just in case other sites don’t do password salting, among other potential reasons.
Rai@lemmy.dbzer0.com 1 day ago
Damn, this is a fantastic writeup, thank you for educating myself (and others, I’m sure!)