Computer: Your password isn't strong enough.  Me: under breath You're not strong enough.  Computer: Okay, honestly? I wasn't the one crying in the breakroom earlier because Linda from Accounting ate my yogurt. Grow the fuck up and pick a better password, little bitch.
you are viewing a single comment's thread
view the rest of the comments
[–] 12 points 2 months ago (2 children)

Correct me if I'm wrong, but if websites store your password in plain text, that's already bad enough. As far as I'm aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense. So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you're using a terrible hashing algorithm). I don't really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 2 months ago

    It's somewhat common to limit password lengths to avoid DoS attacks that exploit a slow key generation function.

    But that limitation should on some hundreds or a few thousands characters. Sites that use limits like "16" are probably storing them as plain text.

  • source
  • parent
  • [–] 4 points 2 months ago

    I appreciate your comment anyway! I didn't know passwords would be hashed to a consistent length - I can see how that would be more secure.

    I don't think in the cases that I mentioned, that the hash of my entered/saved/extralong password was being compared to the stored hash they had on file, I think what happened is the input field validation was changed and would no longer allow a password that was valid under their previous rules.

  • source
  • parent