Small rant incomming. I just went to look at applying to Walmart, and when going to make an account their password requirements were 8-11 characters. What kinda nonsense is that? Some terribly made backend I’d assume. It’s bad enough I gotta make a million accounts when applying to jobs but then you got my PII sitting behind such terrible password requirements it makes me wonder where else they are cutting corners on security.

  • Scott@lem.free.as
    link
    fedilink
    arrow-up
    44
    ·
    1 day ago

    All stored passwords should be salted and hashed. That means each one uses the same amount of space, regardless of original length.

    There should definitely be a minimum length but not a maximum (within limits; let’s not break web standards or the laws of thermodynamics).

    • NullNet@lemmy.blahaj.zoneOP
      link
      fedilink
      arrow-up
      7
      ·
      1 day ago

      you mentioned salting and hashing that reminds me of places that use to put companies on blast for storing passwords in plaintext.

    • ohwhatfollyisman@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      1 day ago

      … 8-11 characters.

      shouldn’t be a problem. take the dwarves and Snow White as a minimum. throw in the evil stepmom, woodsman, and magic mirror if you need them.

  • graycube@lemmy.world
    link
    fedilink
    arrow-up
    11
    arrow-down
    3
    ·
    23 hours ago

    If you allow unlimited length inputs of any kind, someone will break your system. 11 is way too short. But you do need some sort of maximum, even if it is very large.

    • invertedspear@lemm.ee
      link
      fedilink
      arrow-up
      14
      ·
      17 hours ago

      If you’re storing the password in the form the user entered it, you’re doing it wrong already.

      • graycube@lemmy.world
        link
        fedilink
        arrow-up
        3
        ·
        12 hours ago

        Even if you aren’t storing it, if you allow unlimited length someone will break your stuff.

    • Empricorn@feddit.nl
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      19 hours ago

      I just went to look at applying to Walmart

      I’m assuming they meant online. I don’t know what it’s like where you are, but basically every employer requires an account to submit an application…

    • Hamartiogonic@sopuli.xyz
      link
      fedilink
      arrow-up
      10
      arrow-down
      1
      ·
      1 day ago

      Why stop there? 128 or 256 sound much nicer. Actually, while you’re at it, 4096 should be enough to fit a short story.

      • cynar@lemmy.world
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        21 hours ago

        There are use cases where long passwords could be problematic. 64 would be long enough for most purposes, but short enough not to cause issues for things like microcontrollers.

        It should be paired with a strongly recommended larger value, however.

  • shortwavesurfer
    link
    fedilink
    arrow-up
    2
    arrow-down
    2
    ·
    edit-2
    23 hours ago

    I use my password manager to generate 32 character or 64 character passwords whenever possible.

    That’s actually a good part of why I trust cryptocurrency over my bank because my bank has all sorts of personally identifiable information and stupid short password requirements where cryptocurrency has no personally identifiable information and seeds are extremely long and complex.