3 ms·
I don't see why you should limit the length of a password.
by daGrevis 14y ago
I don't see why you should limit the length of a password.
- mosselman 14y agoExactly. In any way in fact. A special char password of 8 char is not more secure than a a-z phrase of 20 long.
- deleted 14y ago[deleted]
- kijin 14y agoI think there is some sense in having a lower limit around 6-8 chars. No matter how many special characters you use, it won't be strong if it's too short. The upper limit of 64 chars is just something that I copy-and-pasted from an actual web app that I wrote some time ago. It works in most cases, but if I were to write the same app now, I'd probably remove the upper limit or make it very large. (By the way, bcrypt only hashes the first 72 bytes of your password [1], so make sure to do something like bcrypt(sha256(password)) if you plan on using longer passwords.) [1] http://news.ycombinator.com/item?id=4515894 http://news.ycombinator.com/item?id=4515894