logoalt Hacker News

xp84last Monday at 11:06 PM1 replyview on HN

I don't think firms like the electric company or (payroll company) ADP are worried that I'll churn.

Also, the Venn diagram of "memorable" and "reasonably secure" really only intersects in the region of "Correct horse battery staple" phrases -- and the problematic sites I'm talking about nearly always limit length, which thwarts that type of password terribly. What is the purpose of maxlength on a password?? These shouldn't be stored in any form other than a hash, so unless long enough to pose a DoS threat during the hashing process, length is truly none of their business.


Replies

charcircuitlast Tuesday at 12:55 AM

The entropy of a hashed password is limited by how many bits long the hash is.