> You can’t just let users paste in 18,000 characters
Thank you for speaking up. And here it is: I don't trust you with my data.
Passwords should not be stored in a database. Period.
So how do you check a password if you can't store it? Hash it with a salt. This results in a fixed width output, regardless of the password size.
If you are setting a max password, it's because you are trying to store it as-is, which is why I don't trust you to store my data.
Edit: I also think it makes sites that do this a target security wise. It's like advertising ignorance.