3 ms·
Which would be fine if all sites used the same rules. But I often find that I can only find the rules when I break them. Such as "password too long > 16 charact
by peterhi 9y ago
Which would be fine if all sites used the same rules. But I often find that I can only find the rules when I break them. Such as "password too long > 16 characters" or "cannot include a space character" (why not?)
- jo909 9y agoThe rules should be, and in my experience often are, explained where you set/change you password. So on the account creation and change password pages. The OP is talking about the login dialog.
- jandrese 9y agoI wouldn't say they are "often" displayed at the password change/set prompt. It's more of a "sometimes" in my experience, although if you get it wrong most sites will then tell you the requirements. I think everyone can agree that hidden requirements are the worst. Some sites do this out of a misguided notion that it gives the hackers information so it must be hidden for security. IMHO, the only requirement that really does anything is length. In my experience it's easier to type a 16 character passphrase than some jumbled up mess that's easy for a computer to guess anyway. Good password (fails many security requirements): "Cokar fed Hunganix!" Bad password (will usually be accepted): "+yP3wr1t3R" I sort of agree with the OP. If you are at a login box and put in an invalid character into the password field, the box should tell you that in the failure message. That may very well jog someone's memory that the site has retarded password policy and they had to modify the password pattern.