Skip to content

Comment on Ask HN: What are valid reasons for limiting password length?

Comments

My bank required that I could only use a 6 character alphanumeric password when signing up. Kind of scary, but then again, it made me choose a super random PW like v3Ff78 whereas most all people in that situation would use their same password for everything, such as baseball. Thats my theory anyway

Even a "super random" 6-character alphanumeric password is not very secure. A brute force algorithm can try the entire space of 6-character strings very quickly. Hopefully they rate-limit login attempts!

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.