Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Really you should not be checking length at all. There is no such thing as a password which is "too long."


From a password security standpoint, I largely agree. You can open yourself to system attacks by allowing arbitrary length input. You should have some kind of limits on any user input.


Sure, but that limit should be closer to hundreds of characters—not 9.


Agreed :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: