3 ms·
> I especially get mad at absurdly small (<200 chars) maximum lengths You realize even the well-regarded bcrypt algorithm only hashes 72 characters, right?
by spb 12y ago
> I especially get mad at absurdly small (<200 chars) maximum lengths
You realize even the well-regarded bcrypt algorithm only hashes 72 characters, right?
- jdpage 12y ago56, actually. It's a major shortcoming of bcrypt, and an argument in favour of algorithms like scrypt and PBKDF2. If you're committed to bcrypt, you could make an argument in favour of digesting the password with something like SHA384 first. That reduces entropy, but (a) it's strictly better than straight SHA, which is what a concerning number of people use already, and (b) it means that you're not messing up the user's pattern/mnemonic if they've got one going.