Just take the string as bytes and hash it ffs

  • @expr
    link
    English
    5818 days ago

    At minimum you need to limit the request size to avoid DOS attacks and such. But obviously that would be a much larger limit than anyone would use for a password.

    • @owsei
      link
      English
      2718 days ago

      Also rate of the requests. A normal user isn’t sending a 1 MiB password every second

    • JackbyDev
      link
      English
      418 days ago

      What’s a sensible limit. 128 bytes? Maybe 64?

      • @owsei
        link
        English
        818 days ago

        I’d say 128 is understandable, but something like 256 or higher should be the limit. 64, however, is already bellow my default in bitwarden