4 ms·
For how much people like to repeat the "Use bcrypt!" mantra I'm amazed no one has mentioned the password length limit of bcrypt. The hash output of bcrypt stop
by throwaway125 14y ago
For how much people like to repeat the "Use bcrypt!" mantra I'm amazed no one has mentioned the password length limit of bcrypt.
The hash output of bcrypt stops changing after 72 characters but almost all bcrypt documentation mentions a 55 character limit. I'm not quite sure what that is about, can anyone clarify?
- shanelja 14y agoI'm unsure of why it is but I don't see why the algorithm can't just handle it like this: check string length if longer than 55, remove first 55 or less characters up to end of string, store in array repeat until string is empty encrypt each item in the array, append them all on to each other as such EncryptedText[0] . EncryptedText[1]... etc Seems like a simple way to handle this. You could impose your own restrictions to stop a server DDoS by encryption requests on long strings, but to be honest if you're allowing a 100,000 character password, you're doing it all wrong.
- mistercow 14y agoThat is potentially problematic, but it's far from the atrocity that is a bank website limiting you to a 10 character password.
- thurn 14y agoBrute-forcing a 55-character password is a transcomputational problem (http://en.wikipedia.org/wiki/Transcomputational_problem http://en.wikipedia.org/wiki/Transcomputational_problem), i.e., it's impossible to accomplish using a computer the size of the earth within the expected lifetime of the earth. So I wouldn't worry too much about it.
- throwaway125 14y agoTo clarify I never meant that the limit is a security issue, just that it's a valid technical limitation to limit the length of a password.