Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The only reasonable restriction is in overall POST body length. I recall an exploit once on node.js where unreasonably large POST requests could DDOS a server with minimal effort.


Well, that and the server having to hash a huge password.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: