hn.today

<input type="password" maxlength="20"> prevents me from logging into Vanguard

tanin.nanakorn.com66 points99 comments
Screenshot of <input type="password" maxlength="20"> prevents me from logging into Vanguard

A developer recounts being unable to log into Vanguard because the password reset form used an HTML password input with maxlength="20". Using a password manager that generates long, secure passwords, a 26-character password was pasted into the reset form and silently truncated to 20 characters by the maxlength attribute. Both the password and confirmation fields on the reset page accepted only those first 20 characters, so the reset operation completed successfully with the truncated value. On the separate login page, the password field did not have the maxlength restriction, so pasting the full 26-character password resulted in a mismatch and an “incorrect password” error, leaving the user baffled after multiple resets.

This demonstrates why using maxlength on password inputs is harmful: it alters the user’s intended secret without clear feedback and can create inconsistencies between pages or clients. The write-up argues that length restrictions should be enforced via client-side JavaScript validation or, preferably, on the backend where the exact submitted text is processed and explicit error messages can be shown. Truncation at the input level breaks interoperability with password managers and leads to frustrating authentication failures, so developers should avoid hard-limiting password inputs in markup.

Read on tanin.nanakorn.com99 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.