6 ms·
Wait really? It feels like almost every time I make a new account somewhere and drop in the 200 character high-entropy password that LastPass generated, I get a
by bro-kaizen 12y ago
Wait really? It feels like almost every time I make a new account somewhere and drop in the 200 character high-entropy password that LastPass generated, I get a silent failure or misleading error message about "your username was not recognized." Then I try guessing which feature of my candidate password is pissing off the site: Is it the whitespaces? Special characters? Length?
This is particularly maddening because there are plenty of ways to accept arbitrary passphrases from users.
- jrockway 12y agoYou use 200 character passwords? I'm happy with 12.
- Springtime 12y agoObviously the longer the maximum available length the better but it does assume the host computer always has the password manager installed. I'd shudder to think how such a long password would be entered otherwise.
- Dylan16807 12y agoOnce you get up to a threshold like 128 bits there's no real benefit in going further. So 22 alphanumeric characters is 'good enough for anyone'.