Comment on NIST proposes barring some of the most nonsensical password rules

<- View Parent
sugar_in_your_tea@sh.itjust.works ⁨1⁩ ⁨month⁩ ago

But it really doesn’t, unless you’re sending megabytes of text or something. Industry standard password algorithms run the hash a lot of times, and your entry will only impact the first iteration.

I usually set mine to 256 characters to prevent DOS attacks, and also so I don’t need to update it ever. Most of my passwords are actually around 20-30 characters in length (I pick a random length in the slider on my password manager), because I don’t want to be there all day if I ever need to manually enter it (looking at you stupid smart TV…).

source
Sort:hotnewtop