3 ms·
I can't believe sites think it's acceptable to do that. I get it, algorithms like Bcrypt have a size limit. But there are reasonably secure ways to get around t
by ShinTakuya 6y ago
I can't believe sites think it's acceptable to do that. I get it, algorithms like Bcrypt have a size limit. But there are reasonably secure ways to get around that, for instance using HMAC to Sha256 the password before Bcrypting it.
Or better yet, pick one of the other algos with better limits and protection like Argon2 or Scrypt.