Correct me if I’m wrong, but if websites store your password in plain text, that’s already bad enough. As far as I’m aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense.
So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you’re using a terrible hashing algorithm). I don’t really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.
Correct me if I’m wrong, but if websites store your password in plain text, that’s already bad enough. As far as I’m aware basic hashing - as in taking the password and transforming it into a fixed length sequence - is (or at least should be) common sense. So if credentials are stored as a hash (or a fixed sequence), then the only logical reason for enforcing a limit on password length should be hash collisions (which are only possible if you’re using a terrible hashing algorithm). I don’t really know what I wanted to say with this, my brain just spontaneously jumped to hashing and the bunch.