Skip to content

Invalid handling of pwds longer than 72 chars with Blowfish #1

@julien-f

Description

@julien-f

Blowfish ignore characters after the 72nd which can cause some issues.

Actual (invalid) behavior:

> hashy <72 'x'>
<hashed password>
> hashy <72 'x' + anything> <hashed password>
ok

Expected behavior:

> hashy <72 'x' + anything> <hashed password>
not ok

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions