54 points•tanin•about 4 hours ago•74 comments•

74 comments

40fourabout 1 hour ago
I’ve ran into this same issue numerous times on different platforms. They silently enforce a max length, unannounced to you, then you can’t log in later until you figure out the correct length.

I guess I don’t really understand the reasons any engineering team would limit password length, but at least implement in a way that is apparent to the user. Successfully saving a password that is different than the user expects is wild.

Moreover, in the case of a financial institution like Vanguard, limiting password length feels particularly offensive.

taninabout 1 hour ago
At least not 20 characters. My generated password isn't insane. It is 4 words with delimiters, so the length varies between 20-28 characters.
walrus01about 3 hours ago
Until just 8 years ago one of the major Canadian nationwide banks was provably storing peoples' online banking logins in plaintext in some ancient mainframe database system. If you got to a sufficiently high level of customer service people in an account recovery process (like executor/probate process for the deceased) they could literally read back to you the entire password letter for letter.

And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: https://www.reddit.com/r/PersonalFinanceCanada/comments/4t0m...

For the Americans who might not be aware of what BMO is (it's not some podunk small town bank): https://en.wikipedia.org/wiki/Bank_of_Montreal

sippingabonedryabout 3 hours ago
> For the Americans who might not be aware of what BMO is

Maybe news hasn't traveled north and broadcast on the CBC, so maybe you haven't heard, but BMO has branches all over the US.

walrus01about 3 hours ago
Yes, as the result of certain acquisitions, much as you can see the banks that TD acquired and rebranded particularly on the US east coast. But not everywhere and not as prevalent as like a Bank of America or Wells Fargo or Citibank. There's huge swathes of the US that have zero BMO brand name presence.

Additionally First Citizens acquired a bunch of "BMO" branchs and is presumably converting them back to their branding.

https://www.google.com/search?client=firefox-b-d&q=first+cit...

andrewstuart2about 3 hours ago
I mean that could still be encrypted. But passwords should never be reversible. It should be hashed with scrypt or apparently now Argon2id.
walrus01about 3 hours ago
I mean literally like if the person's password was "potato##!" the customer service person would read back "potato##!". They weren't reading the encrypted contents of a pw field.
coaksfordabout 4 hours ago
All my worst experiences with password length have been banking and finance and it boggles my mind that they all get something so incredibly basic so incredibly wrong. What is it about this sector that makes it so?
kstrauserabout 3 hours ago
One of my most favorite things in the world was when an org with an outdated security program told me we'd have to rotate our passwords monthly. Then I'd get to tell them that no, we wouldn't, and due to modern security practices, we couldn't without causing a compliance exception.

Sometimes I ended up explaining that to a well-meaning but overworked person who just wasn't aware of the "new" (cough 2017) standard, but they'd ask me for the citation and giggle gleefully, thrilled that they could show their boss that they could knock off that obsolete ritual.

Sometimes I ended up with someone a little smug, because they were at a megacorp and I wasn't, and you'd see the momentary flicker of surprise and uncertainty as they started to wonder if maybe they'd missed something, something very important. I took an unreasonable amount of joy from those interactions.

madamelicabout 3 hours ago
Don't forget blocking paste!

It baffles me why so many sites block paste on bank account number inputs like it is 1995 and we are typing it from checks.

pwgabout 1 hour ago
With Firefox, if one sets the dom.event.clipboardevents.enabled about::config setting to false, then websites can no longer block paste. Your pastes will work, despite their trying to intercept and block them.
ajbabout 3 hours ago
There's an inherent insularity to security groups or fraud teams; they have to have a professional suspicion of everything. This can go wrong and end up being NIH or gratuitously customer-unfriendly.

Also, for finance specifically : " A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional way along with his fellows, so that no one can really blame him." - Keynes

pulvinarabout 3 hours ago
Don't be so hard on them. Their COBOL program is probably limited to 80 character records, so they'll fit on a punched card.
cyodeabout 3 hours ago
+1, plus Ticketmaster for some reason.

I think they use some cursed (or secure I guess) combo of stringent special character requirements, no reuse of old passwords, and automatic resets after incorrect guesses.

It actually hasn’t been an issue after finally using a password manager, but I remember it being a regular headache before that.

Sohcahtoa82about 4 hours ago
I got bit by a similar issue with another service.

I could log into the website just fine, but the app kept saying my password was wrong. I reset my password, and when I was generating a new password, I found the root cause:

At some point, they changed the password policy to have a maximum length of 16 characters. My existing 20 character password worked fine in the website which didn't actually enforce a 20-character limit in the password field, but the app was silently truncating the last 4 characters when BitWarden was filling in the field.

Limiting password length to only 16 characters scares me. It makes me think they're not hashing passwords in the back end.

vegetablepotpieabout 4 hours ago
These are the same companies that state that users are responsible for choosing secure passwords… and then they make this as difficult as possible to do.

Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.

alright2565about 3 hours ago
Well, in the USA as it is, they are already accountable under Reg E for any fraud losses due to a failure of an "access device" aka password. I'm not sure what else you would want.
sippingabonedryabout 4 hours ago
> they make this as difficult as possible to do.

They provided password requirements which he ignored.

> Finance needs to be held accountable.

Accountable for what, exactly?

nemomarxabout 3 hours ago
if the requirements make it less secure, isn't that the issue op is complaining about? max lengths are an anti feature.
lapcatabout 3 hours ago
> They provided password requirements which he ignored.

No, you misunderstood what happened: "Chrome inputs only abcdefghijklmnopqrstu (20 characters) as shown below"

1Password generated a password longer than 20 characters. When pasted, Chrome silently truncates the paste to the input maxlength!

Look at the screenshot: The requirement "Between 8 to 20 characters long" has a green checkmark, because the requirement is satisfied.

techgnosisabout 4 hours ago
And if someone gets into your account and robs you, that's your problem too!

Read the full thread on Hacker News →

Related stories