4 ms·
Why does a site limit password lengths at all? Because at some point, some other limit will be exceeded. For example, HTTP POST size or even working-set size. B
by rbirkby 14y ago
Why does a site limit password lengths at all? Because at some point, some other limit will be exceeded. For example, HTTP POST size or even working-set size. But the question is specifically about low maximum password lengths. This boils down to hashing vs encrypting. Hashing (with or without salt) will produce a fixed-length output. The size of storage for this hash output is pre-determined. For example a varchar(20) for SHA1. For encryption, you have to take the plaintext bytes and produce a ciphertext of a maximum number of bytes to store. Now we have both a limit on the number of input characters, but also on which characters are permissible. Let's say a site allows the Euro symbol, passes that UTF8 byte stream through an encryption algorithm, base64 encodes the result and stores it in a varchar field. The trouble is that the Euro symbol is composed of a 4-byte multi-byte UTF8 sequence - F0 A4 AD A2. If a password system didn't take account of this, they could easily overflow the storage limit and potentially expose internal details via an error message to the user.
The simple answer is just to hash+salt and then to limit the input length to some large value to prevent blowing HTTP POST or process vm limits.