74 comments
I guess I don’t really understand the reasons any engineering team would limit password length, but at least implement in a way that is apparent to the user. Successfully saving a password that is different than the user expects is wild.
Moreover, in the case of a financial institution like Vanguard, limiting password length feels particularly offensive.
And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: https://www.reddit.com/r/PersonalFinanceCanada/comments/4t0m...
For the Americans who might not be aware of what BMO is (it's not some podunk small town bank): https://en.wikipedia.org/wiki/Bank_of_Montreal
Maybe news hasn't traveled north and broadcast on the CBC, so maybe you haven't heard, but BMO has branches all over the US.
Additionally First Citizens acquired a bunch of "BMO" branchs and is presumably converting them back to their branding.
https://www.google.com/search?client=firefox-b-d&q=first+cit...
Sometimes I ended up explaining that to a well-meaning but overworked person who just wasn't aware of the "new" (cough 2017) standard, but they'd ask me for the citation and giggle gleefully, thrilled that they could show their boss that they could knock off that obsolete ritual.
Sometimes I ended up with someone a little smug, because they were at a megacorp and I wasn't, and you'd see the momentary flicker of surprise and uncertainty as they started to wonder if maybe they'd missed something, something very important. I took an unreasonable amount of joy from those interactions.
It baffles me why so many sites block paste on bank account number inputs like it is 1995 and we are typing it from checks.
Also, for finance specifically : " A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional way along with his fellows, so that no one can really blame him." - Keynes
I think they use some cursed (or secure I guess) combo of stringent special character requirements, no reuse of old passwords, and automatic resets after incorrect guesses.
It actually hasn’t been an issue after finally using a password manager, but I remember it being a regular headache before that.
I could log into the website just fine, but the app kept saying my password was wrong. I reset my password, and when I was generating a new password, I found the root cause:
At some point, they changed the password policy to have a maximum length of 16 characters. My existing 20 character password worked fine in the website which didn't actually enforce a 20-character limit in the password field, but the app was silently truncating the last 4 characters when BitWarden was filling in the field.
Limiting password length to only 16 characters scares me. It makes me think they're not hashing passwords in the back end.
Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.
They provided password requirements which he ignored.
> Finance needs to be held accountable.
Accountable for what, exactly?
No, you misunderstood what happened: "Chrome inputs only abcdefghijklmnopqrstu (20 characters) as shown below"
1Password generated a password longer than 20 characters. When pasted, Chrome silently truncates the paste to the input maxlength!
Look at the screenshot: The requirement "Between 8 to 20 characters long" has a green checkmark, because the requirement is satisfied.
Read the full thread on Hacker News →
Related stories
- A Comprehensive Guide to Structured Logging in Gobetterstack.comLobsters · 8 points · over 3 years ago
- Hacker News · 1 points · 4 days ago
- Hacker News · 2 points · 11 days ago
- Hacker News · 3 points · 5 days ago
- Vanguard: Anti-Boost, Pro-Skillriotgames.comHacker News · 1 points · 5 days ago
- Hacker News · 2 points · 3 days ago