4 ms·
Yes, but that would be OK if the login form truncated the password in the same way as the password change form. They'd both arrive at the same hash. Which is wh
by trickstra 6y ago
Yes, but that would be OK if the login form truncated the password in the same way as the password change form. They'd both arrive at the same hash. Which is what the comment above you said. What you describe probably means the password change form actually did run the hash on the full length, while the login form truncated it.
- davchana 6y agoNo, login form did not truncated, it showed javascript error toast that password is longer than acceptable. The initial signup also checked & showed that toast. But the 90 day reset page did not.
- JanisL 6y agoThis is definitely not OK because it reduces the entropy of the passwords without the user knowing this has happened.
- trickstra 6y agoI never said it's OK, I just explained what's happening. Ah, now I understand why I got those downvotes. What I meant by "OK" was that it would "work". It wouldn't exhibit the behavior my parent comment was describing. Not that it would be secure or good practice.
- JanisL 6y agoAh that makes more sense, thanks for clarifying.