3 ms·
Algorithms like bcrypt may have a maximum supported length: for bcrypt, over about 50 characters and things get dicey [1]. If you're running something computati
by ReidZB 9y ago
Algorithms like bcrypt may have a maximum supported length: for bcrypt, over about 50 characters and things get dicey [1]. If you're running something computationally expensive like scrypt tuned properly, you don't want malicious entities to be able to send you a 32K password request, probably - easier to force them to keep it small (like < 50 chars), then block them based on request throughput.
[1] https://security.stackexchange.com/a/39851/1373 https://security.stackexchange.com/a/39851/1373