this post was submitted on 19 Jul 2023
742 points (98.2% liked)
Asklemmy
43856 readers
2267 users here now
A loosely moderated place to ask open-ended questions
Search asklemmy π
If your post meets the following criteria, it's welcome here!
- Open-ended question
- Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
- Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
- Not ad nauseam inducing: please make sure it is a question that would be new to most members
- An actual topic of discussion
Looking for support?
Looking for a community?
- Lemmyverse: community search
- sub.rehab: maps old subreddits to fediverse options, marks official as such
- !lemmy411@lemmy.ca: a community for finding communities
~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~
founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Why would that be a DOS? The hash of something is always the same length. Might only take a bit more time to compute, but a million characters isn't that much with modern hardware. If anything, the risk of collisions would be higher.
Hashing is typically done server-side. So you need to transmit the password to the server and you can't have a truly unlimited data limit. Pretty much every web server will reject requests over some size so while it's entirely reasonable to support something like a 1,000 char password if you really wanted to, having it be truly unlimited with something using a 10 million character password is a security/operational risk in itself.
https://www.djangoproject.com/weblog/2013/sep/15/security/