4 ms·
Not if you assume that attackers are going to automatically try those that don't meet the requirements anyways.
by marxidad 10y ago
Not if you assume that attackers are going to automatically try those that don't meet the requirements anyways.
- justinlardinois 10y agoWhy would you assume that? A site's password requirements are public information, so you should expect an attacker to read them.