Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem isn't just hotmail. Most major banks (amex, chase, etc.) forbid special characters, limit the password length as well, or a combination of both.

Then again, banks are not exactly on the cutting edge of security, though they like to seem like they are. This isn't a surprise considering how shoddily their web apps are built.



I was recently setting up an online account with Charter because my wife and were having issues with the irregular nature of their paper billing. After securing the PIN number that was only on the paper bill that they weren't sending us, I created the account with a 30 character password string that was generated and stored within Password Gorilla. Charter's webapp took the password, which was to long for them, and instead of throwing an error and telling me to choose a shorter password, it truncated it at some arbitrary position to fit their policy. Locked out! Ten minutes get to a human on the phone, another five to explain why someone would use a 30 character password and how they might go about doing it... eventually the password was reset. Good times.


Then again, banks are not exactly on the cutting edge of security, though they like to seem like they are.

Every bank I've ever dealt with has assumed 100% liability for unauthorized transactions, so a bad password affects them financially, not you. Therefore, I don't understand all the complaining about password length.


That's a pretty damn naive statement. Yes, in the end, customers are financially protected. But that doesn't make up for the hours, days or even weeks of phone calls, emails, letters, in-person visits, credit-reporting agency fixes, etc which are necessary to rectify fraud in the banking/finance industry.


A friend of a friend recently had $500 stolen and Chase didn't reimburse him for that, so this doesn't seem to be universal. (On the other hand, Bank of America did issue me a temporary credit for my money that got stolen in the same compromise, so I know it happens sometimes.)


And if it affects them financially you can count on that being forwarded their customers...


Even if they assume 100% of the liability, it's still a PAIN to deal with stuff like that.


Airlines, too. I recently had to enter an alphanumeric password at or below around 12 characters, I think.

Some companies also add so many requirements to the password that I think it does more harm than good to the entropy of it.


I recently was forced to enter a password of not more than 8 characters as part of college applications. I was somewhat flummoxed, because the disposable password I use for applications I want to be able to forget about is nine characters. That is the lowest I have ever seen: I hope that there is noone worse.


Have you try to enter some quote in your password?

http://xkcd.com/327/


For many web services entropy isn't a big deal because they use computationally hard hashing functions and have sensible server-side limits that outright foil brute force attempts.


until their hashes show up on pastebin


Entropy and work factor are basically the same thing, that's why they call it key stretching.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: