Last week, I tried to register for a service and was really surprised by a password limit of 16 characters. Why on earth yould you impose such strict limits? Never heard of correct horse battery staple?

  • Revan343@lemmy.ca
    link
    fedilink
    arrow-up
    1
    ·
    30 days ago

    you probably don’t need to accept more than 1024 anyway.

    OWASP recommends allowing at least 64 characters. That would cover all of my passphrases, including the ones that are entire sentences