• jordanlund@lemmy.world
    link
    fedilink
    English
    arrow-up
    104
    arrow-down
    2
    ·
    1 year ago

    Emojis are known to break systems in certain circumstances due to the way they’re interpreted in certain character sets.

    I guarantee people doing this will not only lock out their own accounts, but may even freeze some authentication servers.

    https://www.pcmag.com/news/want-to-brick-an-iphone-send-some-emojis

    https://www.itechpost.com/articles/75762/20170119/brick-iphone-using-emojis-plus-tricks-dont-know.htm

    • abhibeckert@lemmy.world
      link
      fedilink
      English
      arrow-up
      31
      arrow-down
      2
      ·
      edit-2
      1 year ago

      The website should feed your password straight into a well known hashing algorithm or key derivation function that has undergone a decade or more of careful scrutiny, without any other processing. The output will usually be a fixed length base64 or hex string.

      There’s a short list of about three options that are currently considered acceptable, and a few more are probably fine but are a little too easy to crack these days (e.g. anything that shares the same math as bitcoin… what if someone throws a mining datacentre at your password?)

      If the site breaks, maybe you don’t to be a customer of that service.

    • Kusimulkku@lemm.ee
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      1 year ago

      If some auth server breaks because I put emojis in my password then that’s right and deserved

      • Funwayguy@lemmy.world
        link
        fedilink
        English
        arrow-up
        16
        ·
        1 year ago

        Hahaha, I wish.

        You would be amazed at how ancient and poorly maintained many web servers are on the modern internet. SQL injection still consistently make the top 3 web app vulnerabilities as of 2021. If that isn’t being sanitized properly I don’t expect emojis would be handled much better.

      • jordanlund@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        1 year ago

        For that particular bug, yes, but there have been many other variations on that theme and not limited to Apple tech. I’ve seen it nuke an email send for example because the SMTP server choked on emojis placed in a subject, to, or from line.