4 ms·
Limits on password length smell like plain text storage. Hashes tend to make the length of the password irrelevant (although some bad implementations only look
by fmw 15y ago
Limits on password length smell like plain text storage. Hashes tend to make the length of the password irrelevant (although some bad implementations only look at the first n characters of the string and ignore the rest), but when you store it in a relational database row you need to come up with some arbitrary limit.
- georgefox 15y agoI believe Active Directory has a maximum length on passwords: http://msdn.microsoft.com/en-us/library/system.web.security.activedirectorymembershipprovider.changepassword.aspx http://msdn.microsoft.com/en-us/library/system.web.security.... (See ArgumentException.)
- safeaim 15y agoHope you're not right, as Paypal only let's you use up to 22 chars if I'm not mistaken
- fmw 15y agoI'm not saying that this is the only reason why people come up with a limit on password length, but that I can imagine that some programmers who come up with such a limit do so because of plaintext storage in a fixed length database row (which is the only quasi-technical excuse for a limit I can up with).