3 ms·
I don't think it's just about hashing. When I see restrictions on passwords or other fields, I always assume the worst. If < is not allowed, that's because your
by bmastenbrook 16y ago
I don't think it's just about hashing. When I see restrictions on passwords or other fields, I always assume the worst. If < is not allowed, that's because your password will show up unencoded in HTML somewhere. If $ is not allowed, that's because somebody is afraid that it will actually be treated as a variable reference somewhere. Likewise & or % in URL-encoded data, ' or " in JavaScript, etc.
The most universal and silent restriction seems to be on NUL bytes.