Uploaded image for project: 'phpBB'
  1. phpBB
  2. PHPBB-14465

Remove maximum password length setting

XMLWordPrintable

    • Icon: Improvement Improvement
    • Resolution: Fixed
    • Icon: Major Major
    • 3.3.0-b1
    • 3.1.7-pl1, 3.2.0-b1
    • None
    • None

      There is no point in having this setting, since there is no point in having a maximum password length.
      It will just lower security for users if admins that don't know or don't care about this setting just let them as they are when the board is installed.

      The few cases where way too long passwords can cause a DoS are catched with a hardcoded maximum length of 4096 which should be more than enough for everyone.

            Marc Marc
            Elsensee Oliver Schramm [X] (Inactive)
            Votes:
            4 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: