No, that's the point, you'd never know whether they only validate a subset of the password. Only by testing different variations you would know that less than the whole string still works.
I wouldn't speculate on how common it is but limiting passwords seems to happen more than it should. So maybe many are taking the stealth approach.
One site I know where this happens (at least I experienced it some years ago) was Blizzard. Found out by sheer luck after I clearly fumbled the end of my password and was logged in regardless.
I use auto generated passphrases. It's mostly for the occasions where I need to give the password to someone, without logging into my bitwarden account, on the device. It's a lot easier, for comparable levels of security.
Not really, you have a better chance if you use a completely random set of words. I remember hearing of someone getting their bitcoin stolen from their wallet despite their password being from an obscure Afrikaans poem.
Always something a bit unique, can't make it predictable if someone managed to dump a list of em. This also isn't the formula I used just an example. Random words is also better if your memory is decent, they can even be your salt.
I switched to using word phrases after having to type in these Qjdu37hYdu4sjdh&) |] >[vry monstrosities or communicate them to someone else one too many times.
19 Comments
noride@lemm.ee · 19 pts · 1y
correct horse battery staple
Alk@sh.itjust.works · 7 pts · 1y
How did you steal my password??
UndulyUnruly@lemmy.world · 4 pts · 1y
Witchcraft! Get them!
fxomt@lemm.ee · 6 pts · 1y
einkorn@feddit.org · 6 pts · 1y
And then there are those services that let you enter arbitrarily long passwords in the registration form but only save something like 16 characters.
mike_wooskey@lemmy.thewooskeys.com · 5 pts · 1y
I hate this situation. What horrible design choices in their code!
fxomt@lemm.ee · 3 pts · 1y
amorpheus@lemmy.world · 2 pts · 1y
How would you know?
fxomt@lemm.ee · 1 pts · 1y
amorpheus@lemmy.world · 2 pts · 1y
No, that's the point, you'd never know whether they only validate a subset of the password. Only by testing different variations you would know that less than the whole string still works.
fxomt@lemm.ee · 1 pts · 1y
amorpheus@lemmy.world · 2 pts · 1y
I wouldn't speculate on how common it is but limiting passwords seems to happen more than it should. So maybe many are taking the stealth approach.
One site I know where this happens (at least I experienced it some years ago) was Blizzard. Found out by sheer luck after I clearly fumbled the end of my password and was logged in regardless.
einkorn@feddit.org · 2 pts · 1y
Amen
nutbutter@discuss.tchncs.de · 5 pts · 1y
Toes@ani.social · 5 pts · 1y
People gotta stop doing QkFEcEEkJFcwUkQ=
aQuickBrownFoxJumpedOverALazyDog$nuggle9 is far easier to remember and secure.
Deebster@infosec.pub · 12 pts · 1y
The article is from Bitwarden, which is a password manager - using them you don't need to remember individual passwords (or type them, normally).
Bitwarden does have an option to use passphrases, I just tried it and it gave me washtub-moocher-dominoes.
cynar@lemmy.world · 2 pts · 1y
I use auto generated passphrases. It's mostly for the occasions where I need to give the password to someone, without logging into my bitwarden account, on the device. It's a lot easier, for comparable levels of security.
fxomt@lemm.ee · 5 pts · 1y
Toes@ani.social · 4 pts · 1y
Precisely why I salted it.
fxomt@lemm.ee · 1 pts · 1y
Toes@ani.social · 1 pts · 1y
Always something a bit unique, can't make it predictable if someone managed to dump a list of em. This also isn't the formula I used just an example. Random words is also better if your memory is decent, they can even be your salt.
swab148@lemm.ee · 3 pts · 1y
I'm more of a SphinxOfBlackQuartz,JudgeMyVow:3 kinda guy
criitz@reddthat.com · 2 pts · 1y
I switched to using word phrases after having to type in these Qjdu37hYdu4sjdh&) |] >[vry monstrosities or communicate them to someone else one too many times.
smeg@feddit.uk · 3 pts · 1y
Interesting to see the linked list of the top 100,000 passwords from the Have I Been Pwned data set
Rampyok151@lemmy.dbzer0.com · 2 pts · 1y
Looks like the link is broken now.
Edit: A part of the list can be found here and here.
LOOOOOWTAPERFADE@discuss.tchncs.de · 2 pts · 1y