‹ BackHN Continuity

Thread

<input type="password" maxlength="20"> prevents me from logging into Vanguard

66 points · 99 comments · tanin

  1. bootlooped · · focus · HN ↗
    My biggest question here is are they not just feeding the input into a hash function, why can&#x27;t it be longer than 20 characters?
    1. arkadiyt · · focus · HN ↗
      bcrypt famously only looks at the first 72 bytes of the input. There are ways around that - don&#x27;t use bcrypt, or do bcrypt(sha256(password)), or whatever, but it is not the case that &quot;just feed the input to the hash&quot; removes all length restrictions
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.