Skip to content

Comment on AmEx: "We discourage the use of special characters because..."parent

Comments

I don't understand a lot about keyloggers. How would less characters in a password make it harder to find within a keystroke log?

It's debatable whether that's even true, but the argument goes something like 'if a unique, non dictionary string pops up with some regularity on the keyboard input it is probably a password', and longer strings stand out more against the background. A 1 character string would never stand out, but a 100 character string would stand out after only two uses.

So longer strings have their own vulnerabilities, but these may not weigh as much as the reduced keyspace of using a shorter string. You can pretty much assume that anything 6 characters or shorter has been entered in to a dictionary.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.