Just take the string as bytes and hash it ffs

  • @expr@programming.dev
    link
    fedilink
    English
    5811 months ago

    At minimum you need to limit the request size to avoid DOS attacks and such. But obviously that would be a much larger limit than anyone would use for a password.

    • JackbyDev
      link
      fedilink
      English
      411 months ago

      What’s a sensible limit. 128 bytes? Maybe 64?

      • @owsei@programming.dev
        link
        fedilink
        English
        811 months ago

        I’d say 128 is understandable, but something like 256 or higher should be the limit. 64, however, is already bellow my default in bitwarden