In password security, the longer the better. With a password manager, using more than 24 characters is simple. Unless, of course, the secure password is not accepted due to its length. (In this case, through STOVE.)

Possibly indicating cleartext storage of a limited field (which is an absolute no-go), or suboptimal or lacking security practices.

  • x00z
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    6
    ·
    7 months ago

    The claim was that a limit on passwords implies plaintext storage. It doesn’t. There is no such thing as unlimited on computers.

    • Kissaki@feddit.orgOP
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      2
      ·
      edit-2
      7 months ago

      The claim was that a limit on passwords implies plaintext storage.

      quoting the post:

      Possibly indicating cleartext storage of a limited field (which is an absolute no-go), or

      It was not a claim that it certainly is plaintext storage. It was claimed to be a possibility. AND provided an alternative explanation.

      Maybe you’re more confident than me in good practices and implementations across all services. But I’ve seen enough to know that’s not always the case. It’s good to be skeptical on anything related to security.

      • x00z
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        10
        ·
        7 months ago

        but this in no way indicates clear text password storage.

        It does.

        No it doesn’t.

        • troed@fedia.io
          link
          fedilink
          arrow-up
          6
          arrow-down
          3
          ·
          7 months ago

          It does.

          /80’s hacker turned Software Engineer turned Cybersecurity professional

          • x00z
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            7
            ·
            7 months ago

            Lmao.

            As if my title isn’t almost exactly the same.

    • troed@fedia.io
      link
      fedilink
      arrow-up
      6
      arrow-down
      2
      ·
      7 months ago

      Don’t worry, I’m autistic myself and understand how difficult it can be to parse “it’s thus irrelevant how many characters the user’s password consists of” to mean something besides “all implementations must accept an unlimited amount of characters”.

      I do believe the point was understood by the general reader however.

      • x00z
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        9
        ·
        7 months ago

        What an awful thing to say. Go question your motives.

        • grysbok@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          1
          ·
          7 months ago

          Curiousity: Could you please explain what was awful about the comment you responded to?

          For context, I’m also autistic.