<input type="password" maxlength="20"> prevents me from logging into Vanguard

tanin 55 points 78 comments October 02, 2026
tanin.nanakorn.com · View on Hacker News

Discussion Highlights (20 comments)

fnord77

The thing that always gets me is when certain characters are not allow. Whyyy

bootlooped

My biggest question here is are they not just feeding the input into a hash function, why can't it be longer than 20 characters?

coaksford

All my worst experiences with password length have been banking and finance and it boggles my mind that they all get something so incredibly basic so incredibly wrong. What is it about this sector that makes it so?

Sohcahtoa82

I got bit by a similar issue with another service. I could log into the website just fine, but the app kept saying my password was wrong. I reset my password, and when I was generating a new password, I found the root cause: At some point, they changed the password policy to have a maximum length of 16 characters. My existing 20 character password worked fine in the website which didn't actually enforce a 20-character limit in the password field, but the app was silently truncating the last 4 characters when BitWarden was filling in the field. Limiting password length to only 16 characters scares me. It makes me think they're not hashing passwords in the back end.

aresant

I had a financial advisor tell me once that he loves Vanguard because once he sends people there to buy index funds the web interface is so utterly TERRIBLE that people can't ever figure out how to sell :)

lapcat

[self-promotion] This is exactly why my browser extension StopTheMadness has a feature to warn when your paste or typing exceeds the input maxlength: https://apps.apple.com/app/stopthemadness-pro/id6471380298

vegetablepotpie

These are the same companies that state that users are responsible for choosing secure passwords… and then they make this as difficult as possible to do. Finance needs to be held accountable. They’ve skim off far too much wealth for the value they produced.

greenavocado

Any they don't support TOTP but support passkeys and SMS for 2FA. WTF

happyopossum

> Of course, my generated password is longer than 20 characters Ok, yes - an undisclosed max length that doesn’t throw an error is horrible, *and this is entirely Vanguard’s fault* but what’s with the “of course”? There’s virtually no reason to use a randomly generated password that long, and there have been more than enough stories, anecdotes etc about sites failing on long passwords that throwing an “of course” here is a little overboard. A high entropy random password with 62+ potential characters before including “special characters” with a length of 16 characters is basically un-bruteforceable. It would take 4.6 billion years to brute force at 164.1 billion guesses per second, and vanguard (or anyone else) is gonna notice if you try the 4.77 × 10^28 possible combinations.

dk404930

I should have kept track of how many times I’ve run into this exact issue. I can’t recall which ones specifically, but I am confident it’s been at least three separate services.

quasarj

I had the opposite issue with my power company for a while. The login page had a maxlength but the reset page didn't, so I had a password set that I couldn't enter... at least without modifying the page

pton_xd

I remember a while ago (~2013?) Schwab used to silently! truncate all passwords to 8 characters. Incredible stuff.

walrus01

Until just 8 years ago one of the major Canadian nationwide banks was provably storing peoples' online banking logins in plaintext in some ancient mainframe database system. If you got to a sufficiently high level of customer service people in an account recovery process (like executor/probate process for the deceased) they could literally read back to you the entire password letter for letter. And just ten years ago BMO required passwords to be exactly 6 char, no more, no less: https://www.reddit.com/r/PersonalFinanceCanada/comments/4t0m... For the Americans who might not be aware of what BMO is (it's not some podunk small town bank): https://en.wikipedia.org/wiki/Bank_of_Montreal

geraldwhen

Vanguard needs a full tech overhaul, a clean sweep. The website is legitimately amateur hour and has been for decades.

xdavidliu

recently i noticed logging into vanguard that if I use firefox autofill password, vanguard always says my password is incorrect, but typing it manually it works. I could clear my password from firefox, type it correctly and login, select "remember my password", log back out and back in, and then have it rejected. so I figured that the way to make it work is to have it autofill, then select my username and press space then backspace, which is a no-op. That way, the javascript knows i've entered something, and then it works.

bogometer

There are more of these than you think and its usually financial institutions. I started running into it years ago when I started using a password manager which allowed to generate strings > 20 chars. Most sites worked, but a few key financial sites not so much. I went through the same frustration cycle as, you finally looking at the html. What is even worse is when someone uses DIFFERENT limits for their app vs web.

flufluflufluffy

> This is one example why we shouldn't use the maxlength attribute on the password field. While I acknowledge your issue is incredibly frustrating, it is still good practice to use the maxlength attribute. Yes, it can be bypassed. Yes, you should still check the length on the backend. But it’s one more layer of ensuring sanitary input. Obviously, companies should do a better job of communicating the maximum password length to the user, properly setting the attributes on all inputs, AND if they do enforce a max length, having it be large enough that it ensures a secure password, but we shouldn’t just abandon using the HTML attribute altogether.

nly

My hot take is that almost nobody should be setting _any_ length or complexity requirements on passwords. Instead just enforce the need for at least some kind of second factor, even if it's SMS, TOTP or a magic link by email. If your password hash database is compromised you're screwed anyway, because dictionary attacks scale horizontally, even with slow hashes designed for passwords 'LickMyLiver123!!' isn't necessarily going to hold up just because it's 16 characters. The average vocabulary of a 20 year old native English speaker is perhaps ~50,000 words and I bet when you apply some basic grammar rules, and pragmatic search paths like relying on tonnes of people just smashing !'s on the end of their usual password when a minimum length is enforced, those hashes start to fall quickly.

esafak

> As it turns out, the password field on the login page doesn't set maxlength to 20. This is the real problem. They let him set a password they did not accept.

40four

I’ve ran into this same issue numerous times on different platforms. They silently enforce a max length, unannounced to you, then you can’t log in later until you figure out the correct length. I guess I don’t really understand the reasons any engineering team would limit password length, but at least implement in a way that is apparent to the user. Successfully saving a password that is different than the user expects is wild. Moreover, in the case of a financial institution like Vanguard, limiting password length feels particularly offensive.

Semantic search powered by Rivestack pgvector
8,345 stories · 77,924 chunks indexed