Here is the text of the NIST sp800-63b Digital Identity Guidelines.

    • frezik@midwest.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Some kind of upper bound is usually sensible. You can open a potential DoS vector by accepting anything. The 72 byte bcrypt/scrypt limit is generally sensible, but going for 255 would be fine. There’s very little security to be gained at those lengths.