3 ms·
Hmmm... if your password was password30jf0sd09jga09ja0i9sdfasi09djf0-sdj9faspiodjf and they only used the first 8 characters, you'd think you had a strong passw
by trothoun 13y ago
Hmmm... if your password was
password30jf0sd09jga09ja0i9sdfasi09djf0-sdj9faspiodjf
and they only used the first 8 characters, you'd think you had a strong password, but would really have a very weak password. Hashing then truncating as discussed above would be much safer.
- jlgreco 13y agoReally no reason to truncate after hashing. The output size of any cryptographic hash function should be more than small enough to send down the wire and hash again properly. Really though, just reject passwords over a few KB. Nobody will ever notice that limit except for people trying to fuck with you.