Forums » Bugs

8 char password limit on account creation via website

Mar 31, 2012 zeiris link
No seriously, the password entry field has maxlength=8 set.

I hope that's only a form bug, and you don't actually truncate them when authenticating.
Mar 31, 2012 yodaofborg link
See http://www.vendetta-online.com/x/msgboard/3/25936

and http://www.vendetta-online.com/x/msgboard/2/25300

Password form used to enable a longer password, but passwords are only 8 chars.
Apr 03, 2012 raybondo link
Yeah, we are aware of this and will be adding longer password support.
Oct 10, 2012 Pizzasgood link
Bump

Basic password security is more important than nonsense like Win8.
Oct 10, 2012 vskye link
Agrees. Devs, fix this. This isn't some bs mission update soon(tm) crap.
Oct 12, 2012 yodaofborg link
Yeah Ray, if you say something on April 3rd, it's no longer April fools you know! Don't make me find and bump the thread from 2003 where we told you about this!
Oct 12, 2012 incarnate link
We somewhat mitigated this some time ago with server-side work to prevent brute-forcing of passwords against the server (web/game). This didn't resolve the issue, but it made certain exploit cases more challenging to attack in practice.

This is an important issue to us, it has been discussed recently (this week) and is planned for the near future. Some of the other projects that have take up our time (Windows 8) have been contractually obligated, so it's not really as simple as the external judgement of relative importance.