|
|
|
|
|
by Tostino
494 days ago
|
|
That is such a rookie mistake. It's not some hidden information that bcrypt has a 72 char limit. Pretty widely documented in multiple implementations and languages. How does a company whose only job is security screw that up so badly? |
|
One of the points of the article is that documentation isn’t enough: one cannot allow callers to misuse one’s API.