Skip to content

Comment on Ask HN: 5-digit alphanumeric or 12-digit integer simpler and more secure?

Comments

This is for some password authentication?

I never understand why people restric password length. Why not 12-char alphanumeric? Or 32-char alphanumeric? Most people will use 10-char passwords (or shorter), but those concerned with security could use better.

BTW - I'v got idea how to ensure people will use unique secure passwords on your site. It's a little harsh, but still.

For each new user in registration form calculate 4-letters hash (from user number, timestamp, whatever), and require user to include this hash in his password (and that the password is at least X characters long). User that has favorite password "swordfish" will just use "swordfishX13h" probably, but it's still better than "swordfish".

I think the question is not password related as the key may be used as a UID for a "semi restricted" link.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.