[Cryptography] Spaces in web passwords

Dave Horsfall dave at horsfall.org
Sat Jun 21 11:51:58 EDT 2014


Somewhat crypto-related, I think...

More and more, I'm seeing web forms that do not accept spaces in 
passwords.  One response is to ignore them completely, and another is to 
say outright that spaces are not permitted.

I'm baffled as to the threat model.  We're supposed to use symbols, aren't 
we, so what's wrong with a blank?  Are their backends really that broken, 
or are spaces susceptible to some obscure attack, or what?

Amongst others, I've got mygov.gov.au and appleid.apple.com on this shame 
list.

-- Dave


More information about the cryptography mailing list