go.crypto/blowfish: allow shorter passwords. bcrypt didn't allow one, two and three letter passwords which is a policy decision best left to the user of the code. Some users have legacy issues which require such short passwords to be processed. LGTM=bradfitz R=golang-codereviews, bradfitz CC=golang-codereviews https://golang.org/cl/81800044