top | item 42444790

(no title)

zja | 1 year ago

You truncate passwords to prevent DOS

discuss

order

lesuorac|1 year ago

Why not either show an error or do a client-side hash so there's a fixed length?

orblivion|1 year ago

Showing an error is probably the right thing. Client-side mitigations wouldn't prevent a DOS.