Correct me if I’m wrong, but if websites store your password in plain text, that’s already bad enough. As far as I’m aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense.
So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you’re using a terrible hashing algorithm). I don’t really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.
I appreciate your comment anyway! I didn’t know passwords would be hashed to a consistent length - I can see how that would be more secure.
I don’t think in the cases that I mentioned, that the hash of my entered/saved/extralong password was being compared to the stored hash they had on file, I think what happened is the input field validation was changed and would no longer allow a password that was valid under their previous rules.
Correct me if I’m wrong, but if websites store your password in plain text, that’s already bad enough. As far as I’m aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense. So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you’re using a terrible hashing algorithm). I don’t really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.
It’s somewhat common to limit password lengths to avoid DoS attacks that exploit a slow key generation function.
But that limitation should on some hundreds or a few thousands characters. Sites that use limits like “16” are probably storing them as plain text.
I appreciate your comment anyway! I didn’t know passwords would be hashed to a consistent length - I can see how that would be more secure.
I don’t think in the cases that I mentioned, that the hash of my entered/saved/extralong password was being compared to the stored hash they had on file, I think what happened is the input field validation was changed and would no longer allow a password that was valid under their previous rules.