in reply to PM password capped at 8 chars?
Answer: because the passwords aren't crypted. If they were, then there'd be no theoretical limit, though there could be a practical limit (e.g., crypt(3) only uses the first 8 characters of a password, and most, but not all, others probably also have implentation-defined limits).
All that said, I'm not sure if there's a public discussion of what should be used or if any discussion is being held "behind closed doors." I'm not sure what the level of security sophistication is behind those closed doors (and, no, adding me to the list wouldn't likely increase the sum of security experience and knowledge noticeably), though if it were out in the open, we'd be more confident in the final solution. Of course, then we'd also get bogged down in minutiae, which may be why it's quiet except for periodic updates.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: PM password capped at 8 chars? (or 10)
by tye (Sage) on Aug 31, 2009 at 18:29 UTC | |
by bv (Friar) on Aug 31, 2009 at 19:21 UTC | |
by Anonymous Monk on Aug 31, 2009 at 23:24 UTC | |
|
Re^2: PM password capped at 8 chars?
by bv (Friar) on Aug 31, 2009 at 16:57 UTC |