HN Simulatornew | past | comments | lists | submit | coaksford's commentslogin

At some point you don't want people to enter the bee movie script, but where the word "bee" was replaced with the entire bee movie script again, recursively three times, all into the password field and tie up servers with extremely long requests.

But 20 characters is simply ridiculous.



All my worst experiences with password length have been banking and finance and it boggles my mind that they all get something so incredibly basic so incredibly wrong. What is it about this sector that makes it so?

One of my most favorite things in the world was when an org with an outdated security program told me we'd have to rotate our passwords monthly. Then I'd get to tell them that no, we wouldn't, and due to modern security practices, we couldn't without causing a compliance exception.

Sometimes I ended up explaining that to a well-meaning but overworked person who just wasn't aware of the "new" (cough 2017) standard, but they'd ask me for the citation and giggle gleefully, thrilled that they could show their boss that they could knock off that obsolete ritual.

Sometimes I ended up with someone a little smug, because they were at a megacorp and I wasn't, and you'd see the momentary flicker of surprise and uncertainty as they started to wonder if maybe they'd missed something, something very important. I took an unreasonable amount of joy from those interactions.


Don't forget blocking paste!

It baffles me why so many sites block paste on bank account number inputs like it is 1995 and we are typing it from checks.


With Firefox, if one sets the dom.event.clipboardevents.enabled about::config setting to false, then websites can no longer block paste. Your pastes will work, despite their trying to intercept and block them.

There's an inherent insularity to security groups or fraud teams; they have to have a professional suspicion of everything. This can go wrong and end up being NIH or gratuitously customer-unfriendly.

Also, for finance specifically : " A sound banker, alas, is not one who foresees danger and avoids it, but one who, when he is ruined, is ruined in a conventional way along with his fellows, so that no one can really blame him." - Keynes


Don't be so hard on them. Their COBOL program is probably limited to 80 character records, so they'll fit on a punched card.

+1, plus Ticketmaster for some reason.

I think they use some cursed (or secure I guess) combo of stringent special character requirements, no reuse of old passwords, and automatic resets after incorrect guesses.

It actually hasn’t been an issue after finally using a password manager, but I remember it being a regular headache before that.


Fear of the Compliance monster.

Compliance over action.

Ass covering instead of responsibility.

Security theatre, in other words.

When the consequences for failure are very high but personal reward for success is very low, everyone does everything they can to avoid being held responsible for the consequences.

Note that I didn’t write “avoid consequences”!

That’s different.


In Argentina our password is called username, it gets the password treatment, but the UIs call it login.

I think it has to do with the fact that Banks are heavily driven by nation law and regulation, so it's not engineering folk that are at the helm, rather it's driven by natural language source code written by non technical people that compiles to target code through engineering lackeys. It works for the most part, but you get very weird failure modes.


Probably PCI and other regulations making it difficult to use and thus learn good software, so they develop entire ecosystems in-house

Don't get me started on passkeys, where it seems it was made for people who literally only use one device: their phone.

Every time I prodded for a passkey I have to run a grep in my brain, what app did I use, or what it an extension, under my personal or work email?

A NIGHTMARE, and for what.


At least let me actually use a security key! PayPal already lets you use security keys for 2FA, but it appears they only allow for smartphone based passkeys for some reason. I'm sure these are behind all the TPMs and Secure Enclaves and whatnot, but a security key is still orders of magnitude safer.

My passkey is stored in my password manager and is available across devices with no hassle.

Until you need to log in on some random device. Or inside an in-app browser popup.

Huh? Do you not understand how this works?

So passkey is saved to my account. Account is logged in on multiple devices, secured with an additional pin.

It doesn't matter what device I'm on, I can either use the app on a mobile device or a browser.

Site goes to login, prompts me for passkey, I type in PIN and select the passkey from my password manager.

It's fast and easy to use.

If I am on a random device (which never happens, ever) I would just log in via browser, or use one of my hardware tokens if I were expecting to access something from an unusual device.


Sometimes I need to sign in to a personal Github account on a work laptop, so I hope non-passkey flows keep working. I don't install my personal password manager on a work laptop.

I would use hardware token for that use case

This isn't categorically true either, the real world is delightfully complicated, far more so than you imagine. The way cars interact within a road, as they enter an exit the road, or how they choose their route can all create conditions where adding a lane only makes traffic worse and can reduce both speed and volume during peak traffic hours.


Whether you mistrusted and were betrayed by that trust is binary, but that's like if someone says "radioactivity is a continuum" and you say "I either got hit by a gamma ray or not" as if that settles the question. Really the question was more like "what's the mean time to betrayal?" or "how big of a payoff can someone be trusted with before they have a 50% chance of betraying trust?" or "am I more or less confident that this person can be trusted in this situation?" or any of a dozen other obvious ways that people who seriously consider the issue of trust do so. If you think the binary states are absolute trust and absolute paranoia and there is no in between (as having any in-between makes it a continuum) then you've got a conception of trust that nobody else in the world finds seriously useful.


It could be that the Gimp team and community are so self-selecting, defensive, and idiosyncratic that they drive everyone else who wants to change (read as "improve") it out of the team and community before letting them do anything to fix it. Gimp stands out among applications I've used as having enduring bad UX for decades, and it's hard to imagine a reason for it other than that efforts to improve it are unwelcome. Even Blender, which I once thought was the only thing worse than Gimp, has successfully turned that around. The reputation that Gimp has for its poor UX is not a random coincidence that a cursed meteor struck it of all open source projects, it's an enduring social problem with exactly that team and community that has earned it that reputation. This enduring social problem won't be fixed by this attitude of "we want it a certain way", that's just defensiveness displacing the critical thinking that was actually needed all along.

The suggestion to fork it is in bad faith. A fork goes nowhere unless a critical mass of the development community goes with it, and if you've already driven away the critical mass that could sustain a fork, that can never happen. Don't worry, Gimp is safe, I don't think anyone organized enough to fix its problems thinks it's worth the effort anymore, they're all working on other things instead.


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: