4 ms·
in our app we have a requirement that is similar.. I kicked and screamed and sent them spec documents from the NIST.. no one cared.. we have a max length of 10
by other_herbert 6y ago
in our app we have a requirement that is similar.. I kicked and screamed and sent them spec documents from the NIST.. no one cared.. we have a max length of 10 chars... that SERIOUSLY hurts... 8 and 10 chars are our current requirements... plus some combination of numbers and special chars... WTFBBQ !!!!111...
hypothetically it's "ok" but c'mon..
- yjftsjthsd-h 6y agoI mean, if you insist on a 10-char maximum, then mandating symbols to increase the search space is a good idea, right? (Granted, that doesn't make a 10-char max sane)
- tialaramex 6y agoAllowing symbols increases the search space, but requiring them reduces it. And in practice this effect can be exaggerated when people don't use random passwords but must actually choose a password they'll remember - because what they'll actually do is choose something easy and then shove a symbol in there to meet your requirement. You may well allow 30+ different symbols, or even more, but the users will invariably pick one of a dozen or so that were easiest to reach on their keyboard and they may learn to be shy of characters that sometimes "don't work" such as quote marks and any local currency symbol even if those are easy to type.