Hacker News new | ask | show | jobs
by riquito 4494 days ago
> It's a learning curve for us. That's why this kind of feedback is important.

Then I would suggest you to look out to the opposite problem, denial of service via long passwords (assuming that you correctly use a slow key derivation function).

e.g. Django now accept passwords with at most 4096 bytes because attackers used gigantic passwords that took a long time to hash