The thing I hate is when people make excuses for it. Especially when those people purport to represent the company that made the mistake:
> Besides, 16 character long password can have 2.8 nonillion possible combinations. You are more likely to reuse your passwords and got owned through that than password brute forcing.
That's a terrible excuse for a 16-character limit. Just admit it was a bad decision (probably made a long time ago) and move on.
I had a short email conversation with someone on the Live team. His stance was pretty much what you said: Somewhere, someone screwed up, and now it's sorta ingrained, and since 16 characters allows decent passwords, it's not a high priority to fix.
The stupid part is this[1]: Passwords cannot contain spaces or "non-English" characters.
I've never heard anyone mention all lower case and upper case "letters", either, but I assume both versions are acceptable characters in a password. And I bet numbers are valid too. So... what is your point? (besides being funny, in which you succeeded)
Well, the password guidelines specifically say " The password can contain uppercase letters and lowercase letters. The password can contain numbers." So no ambiguity there.
They are quite clear about what characters are permitted in the password. The not permitted list is redundant, but sometimes repetition is helpful. The argument that Microsoft has somehow incorrectly identified é as "non-English" is bullshit.
I'm not sure that helps. So an English character is any character that can appear in an English sentence? Are the Chinese words mixed in the Firefly English characters, too then? What makes a Chinese loan word different from a French loan word?
This seems a remarkably, stupidly pedantic point. Would Microsoft have created less overall user confusion by using the term non-ASCII and making all the nontechnical users look up what that means?
Comments
The thing I hate is when people make excuses for it. Especially when those people purport to represent the company that made the mistake:
> Besides, 16 character long password can have 2.8 nonillion possible combinations. You are more likely to reuse your passwords and got owned through that than password brute forcing.
That's a terrible excuse for a 16-character limit. Just admit it was a bad decision (probably made a long time ago) and move on.
I had a short email conversation with someone on the Live team. His stance was pretty much what you said: Somewhere, someone screwed up, and now it's sorta ingrained, and since 16 characters allows decent passwords, it's not a high priority to fix.
The stupid part is this[1]: Passwords cannot contain spaces or "non-English" characters.
1: http://help.outlook.com/en-gb/140/cc540536.aspx
Edit: The double stupid here is the fact that non-ASCII is referred to as "non-English". I'm pretty sure e.g. résumé is a correct English spelling.
I find it particularly insulting when a web application tells me my family name has "invalid" characters.
When asked to say the letters of the English alphabet, I have never heard someone include é.
WellthatsfinethenImnotsurewhatelsewouldchangeyourmindaboutwhatcharactersshouldbeallowedintext
When asked to say the letters of the English alphabet, I have never heard someone include space.
I've never heard anyone mention all lower case and upper case "letters", either, but I assume both versions are acceptable characters in a password. And I bet numbers are valid too. So... what is your point? (besides being funny, in which you succeeded)
Well, the password guidelines specifically say " The password can contain uppercase letters and lowercase letters. The password can contain numbers." So no ambiguity there.
They are quite clear about what characters are permitted in the password. The not permitted list is redundant, but sometimes repetition is helpful. The argument that Microsoft has somehow incorrectly identified é as "non-English" is bullshit.
touché
Alphabet != characters
I'm not sure that helps. So an English character is any character that can appear in an English sentence? Are the Chinese words mixed in the Firefly English characters, too then? What makes a Chinese loan word different from a French loan word?
This seems a remarkably, stupidly pedantic point. Would Microsoft have created less overall user confusion by using the term non-ASCII and making all the nontechnical users look up what that means?
I don't like the fact that it broke all my KeePass passwords...
> Especially when those people purport to represent the company that made the mistake
The comment you're quoting specifically asserts that it does not represent the company:
> (I work at Microsoft) but my opinion does not represent that of my company.
For the record, I also work for Microsoft, and my comments also do not represent the company.