Last week, I tried to register for a service and was really surprised by a password limit of 16 characters. Why on earth yould you impose such strict limits? Never heard of correct horse battery staple?

You are viewing a single thread.
View all comments View context
23 points

Not a problem because passwords are hashed, which means they take up a fixed size, and you should have form upload size limits anyway.

permalink
report
parent
reply
6 points

hashed, which means they take up a fixed size

One would hope so anyway,

you should have form upload size limits

The above conflicts directly with OP’s Accept any utf8 string

permalink
report
parent
reply
5 points

I opened an account in 2014 and I’m still uploading my password.

permalink
report
parent
reply
3 points

If you aren’t required to use an upload manager, are you really setting a solid password :thinking:

permalink
report
parent
reply
3 points
*

Ok. Take up to 65,536 bytes of utf8 string. Or better yet. Accept any password length. I mean any. But instead of transmitting it you bcyrpt on their machine and then use the resulting key to hmac sign a recent timestamp that can’t be reused.

permalink
report
parent
reply

Cybersecurity - Memes

!cybersecuritymemes@lemmy.world

Create post

Only the hottest memes in Cybersecurity

Community stats

  • 14

    Monthly active users

  • 79

    Posts

  • 1K

    Comments