On 01/10/2026 12:11 am, Derick Rethans wrote:
On 30 September 2026 22:26:21 BST, "Tim Düsterhus" <[email protected]> wrote:

If a user of a site has a silly long password now, they can still login. If 
this changes to an Exception, then they no longer can, without intervention 
from a site owner, for whom there is now BC break in the language throwing 
random new exceptions *based on user input*.

I agree with Derick's concerns. This change could affect users who chose long passwords because they believed they would be more secure. I don't believe those users should be \'affected.

I support changing the default to argon2, but this change will be a -1 from me as well.

--
Regards,

Jordi Kroon

Reply via email to