DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Remove silly admin password limits

  • colin_e
  • Topic Author
  • Offline
  • New Member
  • New Member
More
20 Jun 2017 15:44 #1 by colin_e
Remove silly admin password limits was created by colin_e
The Vigor 130, and I assume other current Draytek products, arbitrarily limits admin passwords in both length and complexity. Max password length is 23 characters which is tiny by current standards. In addition a large number of fairly innocuous special characters including underscore, hyphen (-), dollar($), forward slash (/) etc. are not allowed.

This makes no sense.

In implementation terms any password entered should be stored in a fixed-length hashed+salted form only, so the length and makeup of the plaintext password have no reason to be limited.

In security terms, given the risks on the 'net these days the last thing we need is to restrict networking equipment to low complexity (and therefore easier to attack) passwords.

This limitation needs to be sent back to the '80s where it belongs. Unlimited length (or at least 128 character) passwords please, and they should allow any character that's safe to type into a web password field.

Please Log in or Create an account to join the conversation.

  • adrianh54
  • User
  • User
More
27 Jun 2017 13:30 #2 by adrianh54
Replied by adrianh54 on topic Re: Remove silly admin password limits
I can't see a need for more than 23 characters but agree all keyboard characters should be possible.

The other thing that is truly stupid .......... you can't change the username from "admin" . The ability to have a random , user choice name increases security dramatically.

Please Log in or Create an account to join the conversation.