> ... if they are hashing the passwords in any form then it doesn't matter how long the password is ...
Max lengths aren't inherently stupid. Presumably no one thinks 250MB password submissions should be handled, so you will be picking some number (possibly imposed on you by your stack).