3 ms·
NIST 800-63b actually recommends against character class requirements[1] in favor of minimum length requirement and blacklists of breached passwords and other o
by bqe 7y ago
NIST 800-63b actually recommends against character class requirements[1] in favor of minimum length requirement and blacklists of breached passwords and other obvious passwords. Sites that require special characters are not following the current best practice.
[1]: https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
- plain-text4ever 7y agoAnd who could even be made to care about password quality, when every level of the industry leaks plain text passwords like a rusty tugboat. It's to the point that I put racial slurs in my passwords, hoping they show up in leak files and databases, in the hopes that it makes it more difficult to host and maintain such leaks.
- tpetry 7y agoIsn‘t any obvious password already in the list of breached passwords? ;)