> we have increased the minimum password length to 48 characters.
Isn't this complete overkill? I suppose this effectively mandates the use of a password manager, but I wonder where the 48 number came from.
Isn't this complete overkill? I suppose this effectively mandates the use of a password manager, but I wonder where the 48 number came from.
Also, since we are talking about hash functions, keys don't even enter the discussion. Hashing is about making password guessing difficult. The length alone doesn't determine how difficult it is anyway, since there are 48 character passwords in popular wordlists. Just enforce 2fa, use argon2 or similar with a minimum password length of 12 and call it a day.
hunter222222222222222222222222222222222222222222