In password security, the longer the better. With a password manager, using more than 24 characters is simple. Unless, of course, the secure password is not accepted due to its length. (In this case, through STOVE.)

Possibly indicating cleartext storage of a limited field (which is an absolute no-go), or suboptimal or lacking security practices.

  • Redjard@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    26
    ·
    13 hours ago

    That is a huge red flag if ever given as a reason, you never store the password.
    You store a hash which is the same length regardless of the password.

    • Cethin@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      43 minutes ago

      Although at some point you’ll get collisions, but I don’t think that’s actually an issue. It still equally hard to guess a password from the hash, there will just be some solutions that are much longer than others.

    • scintilla@lemm.ee
      link
      fedilink
      English
      arrow-up
      8
      ·
      13 hours ago

      Youre right lol. I forgot that hash lengths are different from the actually password length.