That doesn’t help if someone got a list of their hashes somehow. Then an attacker can use their own system to crack them.
And that’s if they aren’t just storing the passwords as clear text to begin with, which length limitations are often a sign of.
Kissaki@feddit.org 5 days ago
Do you check on login attempt protection behavior before creating accounts, and then choose your password length accordingly - longer or shorter?