this post was submitted on 18 Aug 2024
830 points (98.8% liked)

Cybersecurity - Memes

1891 readers
1 users here now

Only the hottest memes in Cybersecurity

founded 1 year ago
MODERATORS
830
submitted 3 weeks ago* (last edited 3 weeks ago) by cron to c/cybersecuritymemes@lemmy.world
 

Last week, I tried to register for a service and was really surprised by a password limit of 16 characters. Why on earth yould you impose such strict limits? Never heard of correct horse battery staple?

you are viewing a single comment's thread
view the rest of the comments
[–] Ptsf@lemmy.world 12 points 3 weeks ago (5 children)

The answer is always a poorly coded database. :(

[–] herrvogel@lemmy.world 17 points 3 weeks ago (4 children)

What? The password should only receive the hashed password, and that's gonna have a fixed length. What's stored in the db should have the exact same length whether the password is 2 characters long or 300. If the length of the password is in any way a consideration for your database, you've royally fucked up long before you got to that point.

[–] Ptsf@lemmy.world 1 points 3 weeks ago

There are going to be very few hashing algorithms that can take a certain byte value and hash it down into a unique smaller byte value. If you miscoded the database and stored the hashed passwords into a value of a fixed length, you have to abide by that length without some trickery or cleaveriness. Is that not the case? Every time I've seen this limitation in wild code that has been the case.

load more comments (3 replies)
load more comments (3 replies)