4 ms·
The issue is not the 20 characters, but the underlying reason for it. There's no technical reason they would need it unless they were storing it insecurely. Gr
by chaz72 11y ago
The issue is not the 20 characters, but the underlying reason for it. There's no technical reason they would need it unless they were storing it insecurely.
Granted it's possible they're limiting it to 20 for a nontechnical reason, but I have some 40-character passwords in a password manager. Long passwords are not only reasonable, but this is a giant alarm bell if they even imply they might be storing them insecurely.
- nicpottier 11y agoWhat are you talking about? Taken to its logical conclusion you would have sites support passwords up to a million characters or else it is a sign that they are insecure. Having some limit is perfectly sane. I also find it a bit "armchair quarterbacky" to be calling out PayPal on security practices. They've been around the block a few times, and though I certainly don't love them, they aren't making rookie mistakes like not-hashing passwords or the like. You are just spreading FUD for no discernable reason. 20 characters while not the epitome of greatness, isn't a sign of the end times.
- pidg 11y ago"armchair quarterbacky" would make quite a good password, but unfortunately it's 1 character over their limit.
- ascagnel_ 11y agoTheoretically speaking, shouldn't a solid salt + hash algorithm always result in a fixed-length string no matter the input password?
- atonse 11y agoIt should, but I think parent is talking about the input string having a limitation, which limits the amount of combinations you could have in your password. My original comment still stands, though, as 20 characters is a large amount of combinations (although I just did some quick calculations to find it's still less than 128 bits... 114 or so).
- jsmeaton 11y agoYou can DOS a site that doesn't have password length enforcement. 20 characters really is too low though, because it rules out a lot of pass phrases. I believe Django allows up to 4mb for the password, which is more than enough for any sane password.