Hacker News new | ask | show | jobs
by misterdai 4732 days ago
Only the support issue, but then I'd have thought that people using really long passwords as normally the ones who'll make an effort to remember / store them. They mention "Encrypted passwords", which would vary the amount of storage required in their database and also make the passwords retrievable if the attacker had gained access to the key / algorithm etc...

I'd had preferred if they used a one way hash instead, obviously with a secure hash algorithm, uniquely salted and rehashed multiple times. All passwords would then be the same length when stored and users wouldn't have to have such a low maximum limit.

There are worse offenders for low character limits, like Adobe with a 12 char maximum. Used to be a site that listed some, just a shame it's no longer available http://web.archive.org/web/20100526105638/http://www.weakpas...