- Home
- All questions
- Question 536
CompTIA Security+ study material · question 536 of 611
An application uses bcrypt and accepts passwords of any length. What must it also enforce?
Show the answer
Answer: B. A maximum length of 72 bytes
Most bcrypt implementations silently truncate beyond 72 bytes, so the extra characters give no additional strength.
Source: OWASP Password Storage Cheat Sheet (OWASP) — OWASP Password Storage Cheat Sheet › Input Limits of bcrypt