Hacker News new | ask | show | jobs
by masklinn 494 days ago
Seems odd to keep the broken one as the default[0], make the "recommended" one so much longer, and provide none which simply errors on overlong passwords.

Also neither seems to warn about the NUL issue.

[0] I assume for compatibility purpose, but it still seems very dubious.