Comment on NIST proposes barring some of the most nonsensical password rules
frezik@midwest.social 1 month agoRules here are 64 as a reasonable maximum. A lot of programmers don’t realize that bcrypt and scrypt max at 72 bytes (which may or may not be the same as 72 characters). You can get around it by prehashing, but meh. This is long enough even for a reasonable passphrase scheme.
daddy32@lemmy.world 1 month ago
Minor note: 64 unicode characters is potentially much more than 72 bytes.