4 ms·
I can see a few problems with that approach: - It's already fairly straightforward to predict how easy a password will be to crack e.g. if you're going to brut
by nsgi 8y ago
I can see a few problems with that approach:
- It's already fairly straightforward to predict how easy a password will be to crack e.g. if you're going to bruteforce dictionary passwords or those with predictable combinations of characters, why not just include those in your password blacklist?
- Randomly suspending users' accounts and telling them to change their passwords is going to annoy them (especially if it happens repeatedly) and consume support resources
- It's overkill unless the service is security critical
- How easy a password is to crack is partly a function of the hash algorithm and salting the entity uses so it may not be the user's fault their password gets broken