4 ms·
Can we add minimum password complexity requirements to this list? There is nothing more annoying than having to adjust my already 128-bits of entropy password b
by maletor 7y ago
Can we add minimum password complexity requirements to this list? There is nothing more annoying than having to adjust my already 128-bits of entropy password because the website feels I need a special character. Plus, now hackers have a guide for what the password looks like.
- bqe 7y agoNIST 800-63b actually recommends against character class requirements[1] in favor of minimum length requirement and blacklists of breached passwords and other obvious passwords. Sites that require special characters are not following the current best practice. [1]: https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
- plain-text4ever 7y agoAnd who could even be made to care about password quality, when every level of the industry leaks plain text passwords like a rusty tugboat. It's to the point that I put racial slurs in my passwords, hoping they show up in leak files and databases, in the hopes that it makes it more difficult to host and maintain such leaks.
- tpetry 7y agoIsn‘t any obvious password already in the list of breached passwords? ;)