Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't know - maximum length/special characters in passwords I find are enforced pretty much everywhere.

I used to keep my KeePass rule pretty liberal. Any 30-character length string would get generated. More than a few times I've had to either decrease the length or remove characters. I had to drop the length and keep it alphanumeric just to avoid the hassle. Plus, typing weird characters on a mobile device gets old fast (thankfully, KeePass exists on Droid, but boostrapping dropbox + KeePass is still annoying).

What's even worse is when password registration silently drops data. You'll register with one password, and attempting to log back in fails because the page that stored the password and the page that you log in on are using two (probably subtly) different decoding methods.



My LastPass is set to 20 characters, alphanumeric + specials. I don't have to bump it down that often, but the majority of sites I register on are quite geeky. It's generally less geeky places such as shops, government services, online banking that don't accept my passwords (yes - exactly the places where I WANT a strong password). Maybe I've run into issues less than you because mine is only 20 characters not 30.

Here's some raw numbers:

Passwords: 336

Average password strength: 97.5 %

Average password length: 17.9 characters

Number of weak passwords: 3

(For reference, a 20 character password with specials is 100%, with just letters and numbers it comes in at 98%)




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: