`` 阻止我登录 Vanguard。
prevents me from logging into Vanguard

原始链接: https://tanin.nanakorn.com/input-type-password-maxlength-20-is-considered-harmful-and-why-i-couldnt-login-into-vanguard/

用户登录 Vanguard 失败是由于长密码处理方式不一致。Vanguard 的密码重置表单设置了 `maxlength="20"`,因此 Chrome 会在用户无感知的情况下,将 1Password 生成的 26 位密码截断为 20 位,并应用到两个密码字段中。重置使用截断后的密码成功完成。 然而,登录表单没有 20 位密码限制,因此 1Password 提交了完整的 26 位密码。Vanguard 将其判定为错误密码并拒绝登录,看起来像是密码重置失败。 这表明,密码字段中的 `maxlength` 可能在用户不知情的情况下修改输入内容。应当改为通过 JavaScript 或后端明确验证密码长度,确保提交的值与用户原本的输入一致。

一名 Vanguard 用户反映,登录表单中的 HTML `maxlength="20"` 会悄无声息地截断密码管理器生成的较长密码。Vanguard 允许设置较长的密码,却没有明确告知或落实登录时的长度限制,因此认证会失败 reportedly。移动应用据称可以接受该密码,这说明问题可能出在不同前端之间的验证规则不一致,而非后端限制。 讨论还扩展到了对金融类网站更广泛的批评,例如随意设置密码长度和复杂度规则、禁止粘贴密码、应用与网站之间的限制不一致、遗留系统难以适配、密码管理器兼容性差,以及认证方式令人困惑。 一些支持者认为,设定密码长度上限仍有必要,可以防止恶意或异常输入;现代密码管理器生成的随机密码也不一定需要非常长。另一些人则强调,应采用密码管理器、Argon2id 等现代密码哈希算法,以及多因素认证(MFA)。 共识是:合理且事先明确说明的长度限制可以接受,但隐藏的 20 字符限制——尤其是会悄无声息地修改密码的限制——属于严重的可用性和安全问题。
相关文章

原文

For the longest time, I couldn't login to my Vanguard account through web.

I reset the password maybe 3 times during the past year, and it still didn't work. I didn't have time to think about it more, so I assumed there was a glitch. I'd just login by scanning the QR code with the Vanguard app on my phone.

Eventually, I've decided to spend some time figuring out, and maxlength="20" is the root cause. Let me explain.

Vanguard has the reset password form where <input type="password"> sets its maxlength to be 20.

I am using 1password with a heightened sense of security. Of course, my generated password is longer than 20 characters. I would copy the password and paste it in the password input field.

For simplicity, let's say my password is abcdefghijklmnopqrstuvwxyz (26 characters) Since the maxlength is 20, Chrome inputs only abcdefghijklmnopqrstu (20 characters) as shown below:

I'd paste the password twice. Once in the password field, and another in the confirm password field. Then, I'd would click submit.

All good. The password reset was a success!

Then, I'd go to the login page and try to login using the same password.

As it turns out, the password field on the login page doesn't set maxlength to 20. Therefore, the pasted password is the full abcdefghijklmnopqrstuvwxyz (26 characters) as shown below:

Vanguard would complain that my password was incorrect. And I would be so confused because I just reset the password.

This is one example why we shouldn't use the maxlength attribute on the password field. Validating the length using JS or on the backend seems superior since it processes the exact text that the user sends... not the unintentionally trimmed text.

联系我们 contact @ memedata.com