2 ms·
Yep, unfortunately for passphrases the maximum acceptable password length on web sites tends to be the #1 factor limiting their use. I created sample passphras
by PwdRsch 10y ago
Yep, unfortunately for passphrases the maximum acceptable password length on web sites tends to be the #1 factor limiting their use. I created sample passphrases and tried them on a handful of different sites to measure the problem. See starting slide 31 in this presentation (PDF): http://www.passwordresearch.com/files/How%20Secure%20Are%20Multi-Word%20Random%20Passphrases%202.01%20-%20ISSA.pdf http://www.passwordresearch.com/files/How%20Secure%20Are%20M...
- criddell 10y agoDo you know why sites would set a low limit? I can understand limiting to, say, a couple hundred characters, but 16 is ridiculous. These days, all anybody is going to store is a salted hash so the passphrase length should be mostly irrelevant. Edit: that's a pretty nice slide deck. Thanks for the pointer.
- dragonwriter 10y ago> These days, all anybody is going to store is a salted hash so the passphrase length should be mostly irrelevant. Since I still run into services where the "forgot password" mechanism emails your current password in the clear, this is unfortunately not as true as one would hope.