Hacker News new | past | comments | ask | show | jobs | submit login

You _should_ argue that there ought to be no limit. There is absolutely no reason why there should be a limit below maybe 4k (and even then, I'm not sure. Perhaps some limit if DOS is concern...).

The only reason why there are limits now is that there is code running on their servers specifically stopping passwords that are longer - which is insane, if you think about it - they are actively preventing people from creating stronger passwords. I'd rather create a 20-30 character password with no specials (which is still massively harder to crack than a 10 char with all possible specials), because it is easier to type in on mobile, but with this system, I couldn't - which is dumb.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: