1/3
2 Years of Service
Haha! Should've known XKCD had a thing about thatThis brings to mind a certain XKCD comic:
You must be registered to see attachments
(Of course the problem with this approach is that there are quite a few websites that insist on you having a combination of lower/upper case characters and numbers AND special symbols in your password, ON TOP of having a hidden limit of 20 characters or less. All gigantic flags of NOPE security wise, but depressingly all too common.)
And, you're right... Many websites have a hidden character limit, including Microsoft (16 length)
Limiting the length of a password is archaic. With current salt+hash methods, the user's password can be virtually unlimited in length. I suspect the main reason to limiting the length of passwords, is to make CPU load predictable. A password of 1MB in size would use many more cycles to process than one of 16 bytes.