Comment on NIST proposes barring some of the most nonsensical password rules
subtext@lemmy.world 1 month agounless you’re sending megabytes of text or something
That’s exactly what someone malicious would do though, either in a single password submission or DOS via the password maximum repeatedly. IMO there is no functional security difference between a 64 and a 256 character password, so the NIST 64 character max is reasonable.