<input type="password" maxlength="20"> prevents me from logging into Vanguard
tanin.nanakorn.com
tanin.nanakorn.com
And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: https://www.reddit.com/r/PersonalFinanceCanada/comments/4t0m...
For the Americans who might not be aware of what BMO is (it's not some podunk small town bank): https://en.wikipedia.org/wiki/Bank_of_Montreal
I agree that it any system that allows this IS almost certainly just storing as plain text, and that it’s bad regardless.
Maybe news hasn't traveled north and broadcast on the CBC, so maybe you haven't heard, but BMO has branches all over the US.
Additionally First Citizens acquired a bunch of "BMO" branchs and is presumably converting them back to their branding.
https://www.google.com/search?client=firefox-b-d&q=first+cit...
I guess I don’t really understand the reasons any engineering team would limit password length, but at least implement in a way that is apparent to the user. Successfully saving a password that is different than the user expects is wild.
Moreover, in the case of a financial institution like Vanguard, limiting password length feels particularly offensive.
Ass covering instead of responsibility.
Security theatre, in other words.
When the consequences for failure are very high but personal reward for success is very low, everyone does everything they can to avoid being held responsible for the consequences.
Note that I didn’t write “avoid consequences”!
That’s different.
It baffles me why so many sites block paste on bank account number inputs like it is 1995 and we are typing it from checks.
Also, for finance specifically : " A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional way along with his fellows, so that no one can really blame him." - Keynes
Every time I prodded for a passkey I have to run a grep in my brain, what app did I use, or what it an extension, under my personal or work email?
A NIGHTMARE, and for what.
I think they use some cursed (or secure I guess) combo of stringent special character requirements, no reuse of old passwords, and automatic resets after incorrect guesses.
It actually hasn’t been an issue after finally using a password manager, but I remember it being a regular headache before that.
Sometimes I ended up explaining that to a well-meaning but overworked person who just wasn't aware of the "new" (cough 2017) standard, but they'd ask me for the citation and giggle gleefully, thrilled that they could show their boss that they could knock off that obsolete ritual.
Sometimes I ended up with someone a little smug, because they were at a megacorp and I wasn't, and you'd see the momentary flicker of surprise and uncertainty as they started to wonder if maybe they'd missed something, something very important. I took an unreasonable amount of joy from those interactions.
I think it has to do with the fact that Banks are heavily driven by nation law and regulation, so it's not engineering folk that are at the helm, rather it's driven by natural language source code written by non technical people that compiles to target code through engineering lackeys. It works for the most part, but you get very weird failure modes.
I could log into the website just fine, but the app kept saying my password was wrong. I reset my password, and when I was generating a new password, I found the root cause:
At some point, they changed the password policy to have a maximum length of 16 characters. My existing 20 character password worked fine in the website which didn't actually enforce a 20-character limit in the password field, but the app was silently truncating the last 4 characters when BitWarden was filling in the field.
Limiting password length to only 16 characters scares me. It makes me think they're not hashing passwords in the back end.
Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.
They provided password requirements which he ignored.
> Finance needs to be held accountable.
Accountable for what, exactly?
A 20 character password is for all practical purposes mathematically immune to being brute forced.
I use strong 12 character passwords at work, on the off chance i have to type them out. And as a favour to anyone else that might have to.
Not magic there, just information theory. but yes, I hear what you are trying to say. It is more cumbersome.
No, you misunderstood what happened: "Chrome inputs only abcdefghijklmnopqrstu (20 characters) as shown below"
1Password generated a password longer than 20 characters. When pasted, Chrome silently truncates the paste to the input maxlength!
Look at the screenshot: The requirement "Between 8 to 20 characters long" has a green checkmark, because the requirement is satisfied.
But 20 characters is simply ridiculous.
The person who wrote it just came up with 20 in the moment and forgot to go check, something everyone has done a hundred times.
I've probably never worked on a single system where the html validation, http server validation, and database constraint were synchronized on username max length. You choose a placeholder, an even number between 10 and 16, then forget to ever check.
CREATE TABLE passwords (
email VARCHAR(MAX),
password VARCHAR(20) UNIQUE -- unique passwords are more secure.
-- NOTE: "20" here because we used to use SHA1 hashes
-- but there was an issue with storing binary in CP437
-- so we just renamed the field.
)Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”?
There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard.
A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.
2. Stupid choices by services (like Vanguard!) making those extra characters a liability.
3. What are you protecting against? Even 16 characters with ~60 combinations is more than enough entropy.
4. It’s just cumbersome. And that, frankly, is the reason why the question is “why should you?”
The possibility of having to manually enter a password is actually why I used to want very long passwords to be allowed.
Say I have a streaming account, which I use from my desktop and maybe my phone or tablet. I never have to enter it manually on those devices because my password manager runs on all of them.
But then I want to use that service's streaming app on my TV. Nowadays most services have figured out a way for you to enter your credentials on their website or in the app on your phone or tablet and link that to your attempt to set it up on the TV, but back in the day most did not.
What we had to do back then is manually enter the password using the on-screen keyboard on the TV, navigated using the up/down/left/right buttons on the remote.
Worse, any time your password switched between symbols, numbers, lower case letters, and uppercase letters you needed to press some kind of shift key.
If long passwords were allowed I could pick a password that only uses say lower case letters from a small group that are right next to each other on the virtual keyboard, like qawe, and make up for the small character set with length. 40 random characters from qawe is 80 bits of entropy which is fine for a streaming account.
While I acknowledge your issue is incredibly frustrating, it is still good practice to use the maxlength attribute. Yes, it can be bypassed. Yes, you should still check the length on the backend. But it’s one more layer of ensuring sanitary input. Obviously, companies should do a better job of communicating the maximum password length to the user, properly setting the attributes on all inputs, AND if they do enforce a max length, having it be large enough that it ensures a secure password, but we shouldn’t just abandon using the HTML attribute altogether.
I think statement from TFA basically boils down to "stop enforcing maxlengths on passwords, neither in the form field nor the DB". I'm no security expert but I'm a `correct horse battery staple`-adherent so if anything, password fields should have a minimum length, not maximum. Short passwords should be what's considered dirty.
For example, a password value of a million characters, to me, would be unsanitary, or unexpected. Of course it’s possible somebody might want to use that as their password, but more likely it’s an attempt at a buffer overflow. I’m not saying there is a specific number where it changes from sanitary to unsanitary, but choosing some reasonable value to limit the length at would be a good idea. Even outside of security, from a purely utilitarian perspective, it would make sense to have some limit on the length of any data you’re storing/processing.
Re: security, yes, there should be a reasonable minimum length as well.
so I figured that the way to make it work is to have it autofill, then select my username and press space then backspace, which is a no-op. That way, the javascript knows i've entered something, and then it works.
If your password hash database is compromised you're screwed anyway, because dictionary attacks scale horizontally, even with slow hashes designed for passwords 'LickMyLiver123!!' isn't necessarily going to hold up just because it's 16 characters.
The average vocabulary of a 20 year old native English speaker is perhaps ~50,000 words and I bet when you apply some basic grammar rules, and pragmatic search paths like relying on tonnes of people just smashing !'s on the end of their usual password when a minimum length is enforced, those hashes start to fall quickly.
Its probably for the best.
Allegedly the new website is coming https://investor.vanguard.com/new-vanguard-experience
It's way better than doing anything with computershare.
This is the real problem. They let him set a password they did not accept.