7 ms·
Gonna guess that's a bad message for a password length violation or something else. Not that it's much better. Is it so hard to allow 50 character passwords?
by duaneb 10y ago
Gonna guess that's a bad message for a password length violation or something else.
Not that it's much better. Is it so hard to allow 50 character passwords?
- bagacrap 10y agoI'm guessing it detected an @ symbol?
- divanvisagie 10y agohas anyone tried password@password ?
- AsyncAwait 10y agoif the password is stored properly, (i.e. bcrypt), the number of characters shouldn't matter at all, be it 50 or 5000.
- deleted 10y ago[deleted]
- drodgers 10y agoIf the password is stored properly, (i.e. bcrypt) then there does need to be some length limit or it becomes too easy to DoS a service by sending it hundreds of megabytes of password to bcrypt. There's no reason for that length limit to be less than 100 characters though.
- dogma1138 10y agoYou are going to be limited by the max http request size way before that. To upload 100s or even more than a few megs you need a multipart message, a password form won't accept MP http requests.
- patates 10y agoOn the back-end there usually is a naive POST handler which happily accepts anything it can parse, unless a mature framework with sane defaults is used.
- cookiecaper 10y agoYep, people who've run marginally popular sites have dealt with this before. Give someone a text box and watch them try to stuff 4GB of content in it. There has to be a cutoff somewhere, but as you note, it should be well outside of the realm of reasonable password lengths (hundreds of characters).
- jsjohnst 10y agoGitHub is the only website I can think of off the top of my head that doesn't limit to an arbitrarily small number (aka <100). Do you name any other "major" websites that allow 100 character passwords?
- snowpanda 10y agoAmazon.com allows 128 characters: https://www.amazon.com/gp/help/customer/display.html?nodeId=10412241 https://www.amazon.com/gp/help/customer/display.html?nodeId=...
- amichal 10y agoAnything built with the popular rails gem devise allows 128 by default [1] https://github.com/plataformatec/devise/blob/88724e10adaf9ffd1d8dbfbaadda2b9d40de756a/lib/generators/templates/devise.rb#L157 https://github.com/plataformatec/devise/blob/88724e10adaf9ff...
- XorNot 10y agoHash the password locally (you are serving JavaScript over SSL right?) and only send the SHA256.
- jensvdh 10y agoNever trust the client.
- XorNot 10y agoThis isn't about trusting the client: it's about your endpoint being able to only accept a SHA256 hash sum from the client (thus: length limited) while allowing the user to input arbitrarily long passwords. They hash in the browser: the only way they can mess with it by producing silly outputs, but that only hurts them.
- sk5t 10y agoIt sort of does matter for bcrypt, surprisingly: http://security.stackexchange.com/questions/39849/does-bcrypt-have-a-maximum-password-length http://security.stackexchange.com/questions/39849/does-bcryp... In the interests of hewing closest to cryptographic reality, I design not to allow a password longer than the algorithm can usefully use.
- Dylan16807 10y agoThat's just a bug. Truncation invalidates the 'stored properly' part of the statement.
- mannykannot 10y agoCould you expand on that? I did not think bcrypt was responsible for storing the resultant hash. The limit appears to be in calculating the hash.
- sk5t 10y agoBcrypt spits out a string, that the caller must store, somewhere. I presume the parent post means that Bcrypt "stores" in its output string a value that, for all practical purposes, varies reliably with the same salt but different plaintext.
- Dylan16807 10y agoThe original phrasing was "stored properly, (i.e. bcrypt)". That's including the hashing as part of the 'storing'. Bcrypt has a size limit, but a size limit is not the same thing as truncating. It's broken code on the front end that truncates instead of doing something like sha512.
- dlubarov 10y agoI think it's best to allow longer passwords for those who use long phrases. It's easier to remember the full phrase than a truncated version. You could show a warning that the extra chars beyond 50-55 will be ignored.
- chrischen 10y agoIt's probably a naive substring detection check.