Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There’s a better way to say this than using words like “moronic.”


Let me try: "outdated and groundless"


There is also a better way of commenting, like providing an alternative or engaging with the substance. A modern site not working with password managers might in fact be moronic to many, especially those on HN.


If the shoe fits.

It's a pet peeve of mine when applications have stupid password requirements. It's an incredibly basic thing to get right. If you can't get that right, good luck with the rest of the application.

The only exception to this is if someone is trying to use outrageously long vaultwarden passwords (eg 100 characters) as that can technically break some ciphers, and doesn't provide meaningful security.


This is a completely solved problem , see https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...


You can just accept the 100 character password and cut it off at something reasonable like 32 characters.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: