• Nat997@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 day ago

    Correct me if I’m wrong, but if websites store your password in plain text, that’s already bad enough. As far as I’m aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense. So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you’re using a terrible hashing algorithm). I don’t really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.

    • marcos@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      1 day ago

      It’s somewhat common to limit password lengths to avoid DoS attacks that exploit a slow key generation function.

      But that limitation should on some hundreds or a few thousands characters. Sites that use limits like “16” are probably storing them as plain text.

    • Clay_pidgin@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      I appreciate your comment anyway! I didn’t know passwords would be hashed to a consistent length - I can see how that would be more secure.

      I don’t think in the cases that I mentioned, that the hash of my entered/saved/extralong password was being compared to the stored hash they had on file, I think what happened is the input field validation was changed and would no longer allow a password that was valid under their previous rules.