Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Vanguard needs a full tech overhaul, a clean sweep. The website is legitimately amateur hour and has been for decades.
  • > This is one example why we shouldn't use the maxlength attribute on the password field.

    While I acknowledge your issue is incredibly frustrating, it is still good practice to use the maxlength attribute. Yes, it can be bypassed. Yes, you should still check the length on the backend. But it’s one more layer of ensuring sanitary input. Obviously, companies should do a better job of communicating the maximum password length to the user, properly setting the attributes on all inputs, AND if they do enforce a max length, having it be large enough that it ensures a secure password, but we shouldn’t just abandon using the HTML attribute altogether.

  • Until just 8 years ago one of the major Canadian nationwide banks was provably storing peoples' online banking logins in plaintext in some ancient mainframe database system. If you got to a sufficiently high level of customer service people in an account recovery process (like executor/probate process for the deceased) they could literally read back to you the entire password letter for letter.

    And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: https://www.reddit.com/r/PersonalFinanceCanada/comments/4t0m...

    For the Americans who might not be aware of what BMO is (it's not some podunk small town bank): https://en.wikipedia.org/wiki/Bank_of_Montreal

  • > Of course, my generated password is longer than 20 characters

    Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”?

    There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard.

    A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.

  • My biggest question here is are they not just feeding the input into a hash function, why can't it be longer than 20 characters?
  • I’ve ran into this same issue numerous times on different platforms. They silently enforce a max length, unannounced to you, then you can’t log in later until you figure out the correct length.

    I guess I don’t really understand the reasons any engineering team would limit password length, but at least implement in a way that is apparent to the user. Successfully saving a password that is different than the user expects is wild.

    Moreover, in the case of a financial institution like Vanguard, limiting password length feels particularly offensive.

  • These are the same companies that state that users are responsible for choosing secure passwords… and then they make this as difficult as possible to do.

    Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.

  • I got bit by a similar issue with another service.

    I could log into the website just fine, but the app kept saying my password was wrong. I reset my password, and when I was generating a new password, I found the root cause:

    At some point, they changed the password policy to have a maximum length of 16 characters. My existing 20 character password worked fine in the website which didn't actually enforce a 20-character limit in the password field, but the app was silently truncating the last 4 characters when BitWarden was filling in the field.

    Limiting password length to only 16 characters scares me. It makes me think they're not hashing passwords in the back end.

Explore Birbla archives