bcrypt famously only looks at the first 72 bytes of the input. There are ways around that - don't use bcrypt, or do bcrypt(sha256(password)), or whatever, but it is not the case that "just feed the input to the hash" removes all length restrictions
No comments yet.