←back to thread

430 points tambourine_man | 1 comments | | HN request time: 0.197s | source
Show context
0xbadcafebee ◴[] No.41881170[source]
Why not just do the 4 english words thing? https://xkcd.com/936/
replies(2): >>41883114 #>>41887616 #
1. pta2002 ◴[] No.41887616[source]
Also, people speak languages other than English, and things like Unicode normalization mean that identical characters can be encoded differently depending on what's being used to type the password in, and I'd be willing to bet most websites don't handle that properly. Not to mention non-latin alphabets, which can be even messier. Good luck explaining to someone that the reason their bank's website isn't matching their password is due to there being two ways to encode "olá" (and there isn't a good way to use a specific one, or know which one was used to set the password!)