Just take the string as bytes and hash it ffs

  • @[email protected]
    link
    fedilink
    English
    5810 months ago

    At minimum you need to limit the request size to avoid DOS attacks and such. But obviously that would be a much larger limit than anyone would use for a password.

    • @[email protected]
      link
      fedilink
      English
      2710 months ago

      Also rate of the requests. A normal user isn’t sending a 1 MiB password every second

    • JackbyDev
      link
      fedilink
      English
      410 months ago

      What’s a sensible limit. 128 bytes? Maybe 64?

      • @[email protected]
        link
        fedilink
        English
        810 months ago

        I’d say 128 is understandable, but something like 256 or higher should be the limit. 64, however, is already bellow my default in bitwarden