Last week, I tried to register for a service and was really surprised by a password limit of 16 characters. Why on earth yould you impose such strict limits? Never heard of correct horse battery staple?

  • Jade@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    Not a problem because passwords are hashed, which means they take up a fixed size, and you should have form upload size limits anyway.

    • tiredofsametab@fedia.io
      link
      fedilink
      arrow-up
      0
      ·
      4 months ago

      hashed, which means they take up a fixed size

      One would hope so anyway,

      you should have form upload size limits

      The above conflicts directly with OP’s Accept any utf8 string

      • x0x7@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        4 months ago

        Ok. Take up to 65,536 bytes of utf8 string. Or better yet. Accept any password length. I mean any. But instead of transmitting it you bcyrpt on their machine and then use the resulting key to hmac sign a recent timestamp that can’t be reused.