Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
All The Tropes Wiki Project, Part XVII
RE: All The Tropes Wiki Project, Part XVII
#27
(08-24-2020, 12:13 PM)robkelk Wrote: Noticed something that made me wonder: Who used a novel-length password, to made it necessary to put a maximum size on them? And why is the maximum set to 4096 characters?

Rhetorical question; no need to answer. It Just Bugs Me, is all.

This is a Denial of Service attack vector.  Logged-out users send large payloads, and the server spends a lot of time computing hash functions.

OWASP Authentication Cheat Sheet - Password Length

I didn't even have to look it up, it just seemed obvious to me.  Which is why I work in application security I guess.
"Kitto daijoubu da yo." - Sakura Kinomoto


Messages In This Thread
RE: All The Tropes Wiki Project, Part XVII - by Labster - 08-25-2020, 01:42 AM

Forum Jump:


Users browsing this thread: 12 Guest(s)