12 ms·You truncate passwords to prevent DOSby zja 2y agoYou truncate passwords to prevent DOSlesuorac 2y agoWhy not either show an error or do a client-side hash so there's a fixed length?orblivion 2y agoShowing an error is probably the right thing. Client-side mitigations wouldn't prevent a DOS.