3 ms·
Would you allow ascii characters under 32? Or would you considere it a dumb rule to disallow them?
by electrotype 7y ago
Would you allow ascii characters under 32? Or would you considere it a dumb rule to disallow them?
- kchamplewski 7y agoFrom a security perspective exclusively, it's completely pointless to disallow them. From a usability perspective, if someone manages to accidentally enter some dodgy control codes, and then can't log in on other devices because they don't know how to enter their password, it may be problematic. Personally I think if a user chooses to put control codes or emoji or the unicode symbol for 1/2 as a fraction in their password, they're entirely welcome to have that but they shouldn't be surprised that when they want to log in they have to enter the password with that in it. Ultimately, it depends on the expense of the support request that arises when users screws up and needs to reset their password - if it's too expensive it may be worth excluding the really exotic characters.