Those characters are disallowed because they would cause delimiting issues for the shell/sed/awk/perl/php crap they are using to process those files, or db injection attacks.
A proper password hashing function takes any byte string.
Those characters are disallowed because they would cause delimiting issues for the shell/sed/awk/perl/php crap they are using to process those files, or db injection attacks.
A proper password hashing function takes any byte string.
There are, actually, a couple of reasonable UX reasons for placing some restrictions on the characters someone can use in a password. If you hope that they will be able to enter the same password from another device later, you want to encourage them not to exploit all the wonderful input possibilities afforded by their plug-in emoji keyboard on their phone. Sadly I don't think this kind of reason underlies any restrictions I've ever seen in the wild.
Except it really isn't, while stupid this is hardly uncommon in software that does hashing.