4 ms·
Here's one reason we don't show password requirements on public pages: If a bad guy has to experiment to find the list of available characters and lengths of a
by romdev 9y ago
Here's one reason we don't show password requirements on public pages: If a bad guy has to experiment to find the list of available characters and lengths of a password, it's easier to for us good guys to track that behavior. Alternatively, listing the password requirements makes it easier for him to truncate the dictionary for his brute force attacks. If he knows we don't accept ampersands in passwords, he'll remove all passwords with ampersands from his list of 10,000 most common passwords when attacking our site.
- darkerside 9y agoHe can easily find this out by creating a single account
- romdev 9y agoMost sites require a email address to create an account, leaving a larger footprint for forensics. The sites I work on require much more personal data that is validated against other systems to confirm identity. Out-of-session page requests are scrutinized for patterns that look like a bad guy checking the locks. Granted, many sites will have client side validation for passwords, but that should be considered a user convenience - not a security measure, and doesn't necessarily have to be as strict as the server side validation. New users won't 'accidentally' enter Unicode escape sequences in passwords, but we need to prevent that on the server side validation and show a generic error "your enrollment failed for some reason" so the bad guy doesn't know if it's input validation or personal data validation that failed.