57
What is with bad password requirements
(lemmy.blahaj.zone)
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Enjoy!
If you allow unlimited length inputs of any kind, someone will break your system. 11 is way too short. But you do need some sort of maximum, even if it is very large.
If you’re storing the password in the form the user entered it, you’re doing it wrong already.
Even if you aren't storing it, if you allow unlimited length someone will break your stuff.