Passwords arbitrarily limited in length
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can someone please explain to me why PayPal has an arbitrary password limit of just 20 characters? My standard minimum is 30 and this really should be the minimum for something like PayPal. Maybe for lesser important sites 15-20 is fine, but for a site like PayPal the limit of 20 is too short.
That said, why is there even a limit? Passwords should be hashed and salted using a strong hashing algorithm. No matter what length your password is it will (should!) always end up as a one-way cryptographic hash. So, having an arbitrary limit is nonsense. It's also an upper bound that an attacker can exploit. It reduces the search space of an attack to 20 characters maximum rather than an unknown upper-bound.
I am both baffled and annoyed that PayPal has such an arbitrary limit in place. Yes, I do use 2FA and that is mitigation; however, this is NOT an excuse for poor practices when it comes to passwords. Rather than setting the maximum to 20 they should be setting this as the absolute minimum and have no upper-bound.
I would love to know what PayPal's thinking is behind this.
-e
- Labels:
-
Login and Password
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Haven't Found your Answer?
It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.
- Limited account and cryptocurrency wallet in Disputes and Limitations Archives
- Account limitation in Disputes and Limitations Archives
- link bank account problem in My Money Archives
- Account Limitations in Disputes and Limitations Archives
- My account arbitrarily permanently limited "Reference ID: PP-L-255785517348" in Disputes and Limitations Archives