Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > Miscellaneous > Feedback

Notices

Reply
 
Thread Tools Search this Thread
Old 02-06-2016, 09:44 PM   #1
Xandaros
Junior Member
Xandaros began at the beginning.
 
Posts: 8
Karma: 10
Join Date: Feb 2016
Device: Kindle PW3 G090 G105
Unable to log in with password longer than 50 characters

Hello,

I registered yesterday and found myself unable to log in from my other machine. Turns out that, when registering (or changing your password), the input boxes are limited to 50 characters. Anything above that simply gets trimmed off.

The log in box on the main page does not have any such restrictions and will happily accepts my 64 character password. What happens next is that I registered with a 50 character password, but try to log in with a 64 character long password. Which is obviously a mismatch.

I may be paranoid for uses such long passwords, but this is clearly a bug. Please fix.
By the way: Why the limit? Looks like you compute the MD5 (insecure, btw) hashes on the client, anyway. On a side note - do you even salt them? Not that it matters with MD5...
Xandaros is offline   Reply With Quote
Old 02-06-2016, 11:23 PM   #2
Cinisajoy
Just a Yellow Smiley.
Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.
 
Cinisajoy's Avatar
 
Posts: 19,161
Karma: 83862859
Join Date: Jul 2015
Location: Texas
Device: K4, K5, fire, kobo, galaxy
Most places require passwords between 8 and 20 characters.
Cinisajoy is offline   Reply With Quote
Advert
Old 02-06-2016, 11:34 PM   #3
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Most places warn you...


That being said, I have never bothered with a 64-character password.
15-20 characters are meaningfully secure already, how much more secure can you get?


On a vaguely similar note (I think), the GnuPG people still tell everyone that RSA-4096 is not really worth it.

Last edited by eschwartz; 02-06-2016 at 11:38 PM.
eschwartz is offline   Reply With Quote
Old 02-07-2016, 12:24 AM   #4
Cinisajoy
Just a Yellow Smiley.
Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.
 
Cinisajoy's Avatar
 
Posts: 19,161
Karma: 83862859
Join Date: Jul 2015
Location: Texas
Device: K4, K5, fire, kobo, galaxy
Quote:
Originally Posted by eschwartz View Post
On a vaguely similar note (I think), the GnuPG people still tell everyone that RSA-4096 is not really worth it.
Please translate this from geek to English.
You confused "the people".
Cinisajoy is offline   Reply With Quote
Old 02-07-2016, 12:38 AM   #5
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Would you know a crypto if it bit you?
Have you ever used an SSH key to remotely login to another computing device via the command line?




Have you ever worried about cryptographically signing your messages or files to prove it was you who wrote it?
Examples:
https://www.gnupg.org/
https://emailselfdefense.fsf.org/en/

Last edited by eschwartz; 02-07-2016 at 12:44 AM.
eschwartz is offline   Reply With Quote
Advert
Old 02-07-2016, 12:39 AM   #6
Cinisajoy
Just a Yellow Smiley.
Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.
 
Cinisajoy's Avatar
 
Posts: 19,161
Karma: 83862859
Join Date: Jul 2015
Location: Texas
Device: K4, K5, fire, kobo, galaxy
Only if it is quiz.


In answer to your question, nope never have.
I have had no need to prove I am me.

Last edited by Cinisajoy; 02-07-2016 at 01:02 AM.
Cinisajoy is offline   Reply With Quote
Old 02-07-2016, 12:50 AM   #7
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Snowden fled to save your soul (from NSA exploitation), you unappreciative... something.
eschwartz is offline   Reply With Quote
Old 02-07-2016, 04:25 PM   #8
Xandaros
Junior Member
Xandaros began at the beginning.
 
Posts: 8
Karma: 10
Join Date: Feb 2016
Device: Kindle PW3 G090 G105
Yes, you're absolutely right - nobody needs passwords longer than 50 characters. People who do that are stupid, let's screw them over by making it so anyone using a password longer than 50 characters is unable to login without warning. Sounds like a very good idea.

...

This is not about whether it makes sense to use such long passwords, this is about how the site handles them.
Xandaros is offline   Reply With Quote
Old 02-07-2016, 05:05 PM   #9
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
I am not saying you are stupid.

I was commenting in response to Cinisajoy -- I said that while it is true many places have an 8-20 character restriction, they warn you of that fact.

Doing proper error checking is ALWAYS necessary.




Given that few people use 50+ characters, I am not completely flabbergasted that the handling for such cases has a bug... but again, I still don't think it is fair to accuse me saying that it is your fault, merely because I said it is unnecessary to use passwords of that length.

I hope I am still allowed to wander in the direction of vaguely, ever-so-slightly offtopic? It is customary in these parts, after all.
eschwartz is offline   Reply With Quote
Old 02-07-2016, 05:30 PM   #10
Cinisajoy
Just a Yellow Smiley.
Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.
 
Cinisajoy's Avatar
 
Posts: 19,161
Karma: 83862859
Join Date: Jul 2015
Location: Texas
Device: K4, K5, fire, kobo, galaxy
Quote:
Originally Posted by Xandaros View Post
Yes, you're absolutely right - nobody needs passwords longer than 50 characters. People who do that are stupid, let's screw them over by making it so anyone using a password longer than 50 characters is unable to login without warning. Sounds like a very good idea.

...

This is not about whether it makes sense to use such long passwords, this is about how the site handles them.
He was not calling you stupid. He was talking to me at that point because I couldn't translate his post.
Cinisajoy is offline   Reply With Quote
Old 02-08-2016, 10:13 AM   #11
Sweetpea
Grand Sorcerer
Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.Sweetpea ought to be getting tired of karma fortunes by now.
 
Sweetpea's Avatar
 
Posts: 9,707
Karma: 32763414
Join Date: Dec 2008
Location: Krewerd
Device: Pocketbook Inkpad 4 Color; Samsung Galaxy Tab S6
Quote:
Originally Posted by eschwartz View Post
Given that few people use 50+ characters, I am not completely flabbergasted that the handling for such cases has a bug... but again, I still don't think it is fair to accuse me saying that it is your fault, merely because I said it is unnecessary to use passwords of that length.
I use a password generator, it generates nice sentences I now have several passwords that are way longer than 20 characters (needless to say, I can't function without my password manager anymore)

You must know this one!

https://xkcd.com/936/
Sweetpea is offline   Reply With Quote
Old 02-08-2016, 11:38 AM   #12
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Yes, I know that one, and it's kind of silly the way dictionary attacks make those far easier than they look (to people who don't realize it is a comic).

I think most people don't realize what Randall was actually saying. People are lousy at generating entropy, but they still think they can do it -- so they do.

Given a string of x length, generated by either correct horse battery staple (CHBS) or pseudorandom characters (`strings /dev/urandom`), pseudorandom always wins.
You can pack a lot more entropy into smaller space. And your password manager is remembering it anyway.

But people being people, who tend to write things down on post-it-notes the webcomic-not-security-analysis is making the point that you will be better served by CHBS than by exchanging "a" --> "@" ad nauseam.
Of course there are other rules too, chiefly the adage about the bear.
Also the one about (not) using MD5.
eschwartz is offline   Reply With Quote
Old 02-08-2016, 12:48 PM   #13
Cinisajoy
Just a Yellow Smiley.
Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.
 
Cinisajoy's Avatar
 
Posts: 19,161
Karma: 83862859
Join Date: Jul 2015
Location: Texas
Device: K4, K5, fire, kobo, galaxy
To the OP,
My best advice is shorten your password for Mobileread.
That way you can log in from any device.
Cinisajoy is offline   Reply With Quote
Old 02-08-2016, 08:26 PM   #14
Xandaros
Junior Member
Xandaros began at the beginning.
 
Posts: 8
Karma: 10
Join Date: Feb 2016
Device: Kindle PW3 G090 G105
Right, so... When I did in my last post here is called an exaggeration. You may have heard of it before, but if not: https://en.wikipedia.org/wiki/Exaggeration (Also a fair amount of sarcasm)
I was mere trying to express my annoyance that people seem to fail to see the point of this post. (I even included that bit about me being paranoid in the first post. Take a hint...)

@Sweetpea: Yes, I remember that one!

@eschwartz: I also use a password generator. That's why I can afford to use insanely long and unique passwords everywhere. It's just a shame that there are so many websites that handle long passwords very poorly. (This being one of them)

@Cinisajoy: There is no way for me to not shorten it, considering it being trimmed down caused me to being unable to log in in the first place. I did generate a new, exactly 50 character long, password, though.
Whatever the case, you are missing the point, though. I'm not looking for a solution to this problem. The solution is obvious: Use a shorter password.
I am also not concerned about the security. 50 characters is plenty, the MD5 issue is about as bad as t gets, anyway. (Might as well store them in plain text at this point)

No - this is in the Feedback subforum and I'm giving feedback about a bug I encountered on the website and hope that someone fixes it. It's not like this can be solved by removing 28 characters from some files or anything... oh, wait.

Last edited by Xandaros; 02-08-2016 at 08:30 PM.
Xandaros is offline   Reply With Quote
Old 02-08-2016, 08:58 PM   #15
Cinisajoy
Just a Yellow Smiley.
Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.Cinisajoy ought to be getting tired of karma fortunes by now.
 
Cinisajoy's Avatar
 
Posts: 19,161
Karma: 83862859
Join Date: Jul 2015
Location: Texas
Device: K4, K5, fire, kobo, galaxy
Glad you didn't need my solution but someone else might.
Perhaps someone will put a password length warning now that they know about the problem.

Oh and there are free drinks in the lounge area.
Cinisajoy is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
PRS-T1 Built-in Reader Store App: Unable to log out? nosnoop Sony Reader 3 06-21-2013 06:14 PM
PRS-T1 Rooted prs t1 Password Locked-Unable to access!!! Vivek982 Sony Reader Dev Corner 6 06-11-2012 04:26 AM
Kobo Website - unable to log in nogle Kobo Reader 2 02-26-2012 09:56 AM
Unable to change the password aditya3098 Kindle Developer's Corner 4 01-29-2012 02:37 AM
Unable to log into eLibrary. chezypuffs Sony Reader 11 12-24-2008 07:52 PM


All times are GMT -4. The time now is 09:59 AM.


MobileRead.com is a privately owned, operated and funded community.