Hacker News new | past | comments | ask | show | jobs | submit login

Wow a whole blog post on the presumption that not allowing some special characters means they are vulnerable to an sql injection attack.

How about.. testing that theory?

Who cares if they're not actually vulnerable? It's 2012. These password restrictions are arbitrary and anachronistic.

They are also the kind of policies that will make enterprisey minds feel safe and secure. Not worth reading too much into them.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
