Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can see reasons for requiring non-alphanumeric characters in a password (even though the reasoning behind that might not be valid). But why the hell you would want to forbid using them, is beyond me. Still I've seen this in pretty many sites, even modern ones.

Maybe they don't have proper parametrized queries and are afraid of SQL injections :)



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: