Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your password must contain at least one special character. Except !, that isn’t allowed.


Worst think about 1password, and lastpass when I uses it, it doesn't let you pick what special characters it uses, despite it being such a common thing on websites. So you have to manually add them, or swap out thing.


Surprising since Keepass has had that for years


Enpass’ password generator has a field were you can enter characters not allowed.

Regretfully Enpass doesn’t store this field nor the rest of the complexity rule as part of the password entry. The next time when password has to be changed you have to figure out the underlying complexity rule again.


I just add a random thing to the end of the password that fits the criteria


Bitwarden let's you choose


The old “abchkkunenukzimejienejsidmdjiwknevgjk bgiknhhhnnisplwkslandhgabsndmskalpaapowhsoslxiaiapjsbsnsnaja” is not secure, but “P@55w0rd” is super duper secure.


in our app we have a requirement that is similar.. I kicked and screamed and sent them spec documents from the NIST.. no one cared.. we have a max length of 10 chars... that SERIOUSLY hurts... 8 and 10 chars are our current requirements... plus some combination of numbers and special chars... WTFBBQ !!!!111...

hypothetically it's "ok" but c'mon..


I mean, if you insist on a 10-char maximum, then mandating symbols to increase the search space is a good idea, right? (Granted, that doesn't make a 10-char max sane)


Allowing symbols increases the search space, but requiring them reduces it.

And in practice this effect can be exaggerated when people don't use random passwords but must actually choose a password they'll remember - because what they'll actually do is choose something easy and then shove a symbol in there to meet your requirement. You may well allow 30+ different symbols, or even more, but the users will invariably pick one of a dozen or so that were easiest to reach on their keyboard and they may learn to be shy of characters that sometimes "don't work" such as quote marks and any local currency symbol even if those are easy to type.


Could be worse.

They might write it on a flipboard next to a window.

https://grahamcluley.com/plymouth-passport-offices-pitiful-p...


The scariest one is when ' is not allowed.


Must include 1 special character, except for the following: ;`'"-


"Our client-side Javascript should be enough to prevent any SQL injection attempts" /s


My favorite one is when it silently removes those characters but doesn't tell you...





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: