3 ms·
It lacks the most infuriating rule found in the wild, an upper limit on the length of the password (that's not at least in the thousands due to e.g. request siz
by ssl232 5y ago
It lacks the most infuriating rule found in the wild, an upper limit on the length of the password (that's not at least in the thousands due to e.g. request size limits).
- charcircuit 5y agoAssuming an random alphanumeric password and a 256 bit hash there is no benefit going above a 55 character password. Even if you aren't just using random characters I think 100 is a fine limit. Most people are not going to be using a password that long without a password manager. If they are using a password manager they might as well just use a random password. For there to be more security in allowing passwords thousands of digits long the host would very likely being storing your password in plain text as opposed to pulling out a few thousand bytes out of an XOF (extendable output function).
- ssl232 5y agoI am aware that there is an upper limit on security provided by longer passwords, but websites should still not set arbitrary upper limits on length from a usability point of view. If I want to use a longer password because that's the default my manager generates, let me.
- erik_seaberg 5y agoI think most people complaining about this on real sites are trying to use a passphrase of thirty-ish letters and spaces, and finding they can't.
- afiori 5y agopasswords are not attacked with random noise, a 55 letter password of 7 common words has way less entropy that 256 random bits. in my opinion password size should be oriented towards preventing DoS attacks, little more (also you can prehash the password on the client with a quick non-password specific but still cryptographically strong hash and then use a proper hash server side, so that on the network all passwords are 256 bits