Just take the string as bytes and hash it ffs

  • @[email protected]
    link
    fedilink
    English
    5824 days ago

    At minimum you need to limit the request size to avoid DOS attacks and such. But obviously that would be a much larger limit than anyone would use for a password.

      • @[email protected]
        link
        fedilink
        English
        824 days ago

        I’d say 128 is understandable, but something like 256 or higher should be the limit. 64, however, is already bellow my default in bitwarden