Why websites have password length limits, if they’re hashed anyway?

271 views

Why websites have password length limits, if they’re hashed anyway?

In: 16

5 Answers

Anonymous 0 Comments

Ignorance and stupidity. Here’s the UK [cyber security centre’s recommendations](https://www.ncsc.gov.uk/collection/passwords/updating-your-approach). You’ll see they explicitly recommend against complexity requirements. It’s counterproductive.

> you should specify a minimum password length, to prevent very short passwords from being used. Avoid using any maximum length requirements that a user might try to exceed, as they will make it harder for users to choose a suitable password that fits the length criteria

You are viewing 1 out of 5 answers, click here to view all answers.
0 views

Why websites have password length limits, if they’re hashed anyway?

In: 16

5 Answers

Anonymous 0 Comments

Ignorance and stupidity. Here’s the UK [cyber security centre’s recommendations](https://www.ncsc.gov.uk/collection/passwords/updating-your-approach). You’ll see they explicitly recommend against complexity requirements. It’s counterproductive.

> you should specify a minimum password length, to prevent very short passwords from being used. Avoid using any maximum length requirements that a user might try to exceed, as they will make it harder for users to choose a suitable password that fits the length criteria

You are viewing 1 out of 5 answers, click here to view all answers.