Cost of calculating 10k character hash? IMO above 30 length serves no practical purpose.
Still, you have a point that allowing arbitrary sized passwords to denial-of-service attacks. Still, a more reasonable limit would be 100 or 256, for example.
Irrelevant compared to the rest of the operations done on the server.