Hacker News new | ask | show | jobs
by bro-kaizen 4175 days ago
Wait really? It feels like almost every time I make a new account somewhere and drop in the 200 character high-entropy password that LastPass generated, I get a silent failure or misleading error message about "your username was not recognized." Then I try guessing which feature of my candidate password is pissing off the site: Is it the whitespaces? Special characters? Length?

This is particularly maddening because there are plenty of ways to accept arbitrary passphrases from users.

1 comments

You use 200 character passwords? I'm happy with 12.
Obviously the longer the maximum available length the better but it does assume the host computer always has the password manager installed. I'd shudder to think how such a long password would be entered otherwise.
Once you get up to a threshold like 128 bits there's no real benefit in going further. So 22 alphanumeric characters is 'good enough for anyone'.