HN
Hacker News
Top
New
Best
Ask
Show
Jobs
Comment by zja | Hacker News Reader
Parent
Full thread
zja
·
You truncate passwords to prevent DOS
View on HN
lesuorac
·
Why not either show an error or do a client-side hash so there's a fixed length?
orblivion
·
Showing an error is probably the right thing. Client-side mitigations wouldn't prevent a DOS.
Reply on news.ycombinator.com