Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Without a limit on password length, an attacker can DOS you by forcing you to run your KDF on gigabyte-sized strings.


Giga byte sized strings?

Oh, no. That doesn't make sense. You need to limit by Giga grapheme strings.


They're only denying service to themselves if you run the KDF locally.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: