Comment on NIST proposes barring some of the most nonsensical password rules

<- View Parent
subtext@lemmy.world ⁨1⁩ ⁨month⁩ ago

unless you’re sending megabytes of text or something

That’s exactly what someone malicious would do though, either in a single password submission or DOS via the password maximum repeatedly. IMO there is no functional security difference between a 64 and a 256 character password, so the NIST 64 character max is reasonable.

source
Sort:hotnewtop