3 ms·
From a security perspective exclusively, it's completely pointless to disallow them. From a usability perspective, if someone manages to accidentally enter som
by kchamplewski 7y ago
From a security perspective exclusively, it's completely pointless to disallow them.
From a usability perspective, if someone manages to accidentally enter some dodgy control codes, and then can't log in on other devices because they don't know how to enter their password, it may be problematic.
Personally I think if a user chooses to put control codes or emoji or the unicode symbol for 1/2 as a fraction in their password, they're entirely welcome to have that but they shouldn't be surprised that when they want to log in they have to enter the password with that in it.
Ultimately, it depends on the expense of the support request that arises when users screws up and needs to reset their password - if it's too expensive it may be worth excluding the really exotic characters.