> Length between 7 and 33 characters
I've never understood why sites limit password length. You're (hopefully) hashing it anyways; the length of what the user enters has no bearing on what you're storing in your database.
I've never understood why sites limit password length. You're (hopefully) hashing it anyways; the length of what the user enters has no bearing on what you're storing in your database.
What if they upload a GB or TB binary as password? I've always wondered but nobody told me if there's some inherent cut-off that would prevent such a DoS attack.