4 ms·
Super long is >100 character passwords. Not much point: either the hash function is broken or some other hack will happen before humanity develops enough comput
by ThreeToZero 5y ago
Super long is >100 character passwords. Not much point: either the hash function is broken or some other hack will happen before humanity develops enough compute power to crack 100 char bcrypt passwords.
Websites (like some banks used to) that have less-than 20 char limits for passwords are purely bad security strategy.
- mooreds 5y agoYou know what the worst is? When they limit you to, say, 20 or 32 characters, but accept a longer password and silently truncate it! I've run across that at least once and it was a total pain to troubleshoot and figure out.
- GordonS 5y agoThe number of sites that restrict passwords to 20 characters drives me nuts! There needs to be a limit, yes, but surely something like 100 characters, or even 50, would be more sensible.
- BlueTemplar 5y agoAnd it's the same websites that tend to use the bad practice of forcing the use of 2-4 "types" of characters...
- userbinator 5y agolike some banks used to Banks all have systems that will stop you from attempting to bruteforce them.