DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Remove silly admin password limits
- colin_e
- Topic Author
- Offline
- New Member
Less
More
- Posts: 4
- Thank yous received: 0
20 Jun 2017 15:44 #89134
by colin_e
Remove silly admin password limits was created by colin_e
The Vigor 130, and I assume other current Draytek products, arbitrarily limits admin passwords in both length and complexity. Max password length is 23 characters which is tiny by current standards. In addition a large number of fairly innocuous special characters including underscore, hyphen (-), dollar($), forward slash (/) etc. are not allowed.
This makes no sense.
In implementation terms any password entered should be stored in a fixed-length hashed+salted form only, so the length and makeup of the plaintext password have no reason to be limited.
In security terms, given the risks on the 'net these days the last thing we need is to restrict networking equipment to low complexity (and therefore easier to attack) passwords.
This limitation needs to be sent back to the '80s where it belongs. Unlimited length (or at least 128 character) passwords please, and they should allow any character that's safe to type into a web password field.
This makes no sense.
In implementation terms any password entered should be stored in a fixed-length hashed+salted form only, so the length and makeup of the plaintext password have no reason to be limited.
In security terms, given the risks on the 'net these days the last thing we need is to restrict networking equipment to low complexity (and therefore easier to attack) passwords.
This limitation needs to be sent back to the '80s where it belongs. Unlimited length (or at least 128 character) passwords please, and they should allow any character that's safe to type into a web password field.
Please Log in or Create an account to join the conversation.
- adrianh54
- Offline
- Member
Less
More
- Posts: 428
- Thank yous received: 0
27 Jun 2017 13:30 #89184
by adrianh54
Replied by adrianh54 on topic Re: Remove silly admin password limits
I can't see a need for more than 23 characters but agree all keyboard characters should be possible.
The other thing that is truly stupid .......... you can't change the username from "admin" . The ability to have a random , user choice name increases security dramatically.
The other thing that is truly stupid .......... you can't change the username from "admin" . The ability to have a random , user choice name increases security dramatically.
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek