DISCLAIMER: Posting this as a concerned player who values security over anything else, not as a staff! Currently, the maximum password length is 12, and a minimum length isn't enforced. I'm wondering if any of you would like to be able to have an even longer password, say, maybe of length 16 or even 20 to better protect your accounts. For me, I'd definitely love to have longer passwords if possible, and I believe it is definitely healthier for the server when minimum password length is enforced (say, minimum of 8 characters). Assuming this is possible, what are your thoughts about it? i.e. if implemented, will you change your password to increase it's length (e.g. from 12 to 14...), etc? Discuss~
Why have a maximum? inb4 I make my password the entire Bee Movie script. Srs tho. I'd love to see a way to auto-fill passwords. Longer passwords are such a headache when you're switching between *cough* like 12 accounts. Maybe tie it to computer/IP and if either changes it requires re-entering? Kind of like what Blizzard does with their battlenet thing. Log in once and you can enter their games without entering a password, but if you change computers/log in somewhere new, it requires a password.
i think the biggest security add would be to allow and then require special characters in passwords. this would help out those people who reuse passwords at insecure private servers
Why even is there a maximum password length in the first place? That's such a huge security oversight. The only fathomable reason that a password maximum would exist is for technical reasons. But I'm sure whatever the cost of upgrading the system to allow longer passwords would be worth it for greater security.
We didn't decide on the password limit, it is just limited in the client by default. We will consider increasing the limit if we can figure out how to.
Autofill password sounds super insecure. Didn’t you guys already had enough people in reports writing that a family member entered their character and commited the offence? now they’ll actually have a backing from your systems to tell those lies, or actually having this sort of thing happen (especially account sharing). Btw, this kind of system will cause people to quickly forget the password, considering they wont type it as much
what happens if you had a 7 character password? because if u had a 13 character password, u only had to use the first 12 characters of it, but what happen if u used a 7 characters password?
Good question. I believe Kevin fixed this issue already when we increased the max length of passwords from 12 to 100. So if you've a 7-character password, you can still login without any issues. But if you try to change the password or create a new account, minimally it must have 8 characters.
well, i ask because i cant login on my accounts with 7 characters password.... first i thought they got hacked, but then i managed to reset a password, and nothing changed on my accounts, so the password must be the problem.... but for my other accounts i dont know the emails i used 4 years ago, also freenet, banned many of them...
In that case, make a ban appeal so an admin can help you out. Locking this thread as the feedback has been implemented.