I just made a new account with some eGov service (Belgian government). I use LastPass (which generates long, random strings for each site),
But the system told me that the maximum allowed length was 16 ASCII symbols. Why do people do this? If they hash it, then the length should not matter, right?
Is there a reason for this? I cannot see a any good explanation for this. What am I missing something here?