We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Password policy

Options
Neither user registration and password reset page for at least the forum and Credit Club state the maximum length of password. Only after examining the source of both pages do I discover that the maximum length appears to be 20 characters. That is, the second, "confirm password", input field is defined as 20 characters, despite the initial "enter password" field being defined as 50 characters.

It says to choose a strong one, but it would appear we are limited to only 20 alphanumeric characters…

You also appear to have a script enabled that attempts to prevent the pasting of passwords, which only encourages the use of "simple" strings.

Comments

  • Thanks for the feedback sderrew.

    I've sent it to our Credit Club team and will take a look at the Forum registration page.
    Could you do with a Money Makeover?


    Follow MSE on other Social Media:
    MSE Facebook, MSE Twitter, MSE Deals Twitter, Instagram
    Join the MSE Forum
    Get the Free MoneySavingExpert Money Tips E-mail
    Report inappropriate posts: click the report button
    Point out a rate/product change
    Flag a news story: news@moneysavingexpert.com
  • MSE_Chris
    MSE_Chris Posts: 212 MSE Staff
    Eighth Anniversary 100 Posts Photogenic Name Dropper
    Hi sderrew

    Thanks for your feedback on this. We're aware there's currently a mismatch when entering passwords in that there's essentially a 20 character limit despite the first box allowing for 50 characters. I've raised this with our tech team but at the moment, they're looking at other improvements that can be made but it is on the 'to do' list.

    Whilst we still allow for the use of special characters, meaning you're still able to set a complex password, we intentionally prevented the use of pasting into the password field. The logic behind this was to prevent against any 'brute force' attacks on this page. However, as in your case, we're aware a number of our users use 'password managers' to help store passwords.

    Ensuring our users accounts remained secure was our top priority which is why on top of this, we also ask users to enter a memorable word. This coupled with the 20 character password limit should be enough to ensure your account remains secure.

    I appreciate not being able to use a password manager is frustrating but we'll continue to look at how we can allow these in the future without compromising security.

    I hope this answers your question.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.7K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.