3 ms·
Raised to 256 Chars
by httphub 12y ago
Raised to 256 Chars
- lotsofcows 12y agoGreat, but why is there a limit in the first place? It implies you're not hashing passwords.
- httphub 12y agoGood password hashing functions will not be much impacted by password length. If you stores the password with 128 bit (salted and key-stretched) hash, there's no gain in allowing passwords longer than 64 characters. Basically, limit the size of input parameters helps preventing DOS and Buffer Overflows.