8 ms·
This is actually a pretty decent list. For the password requirements, I would actually always show them as a list of bullet points (length, casing, special cha
by bbx 5y ago
This is actually a pretty decent list.
For the password requirements, I would actually always show them as a list of bullet points (length, casing, special character, number, no name…) which would validate on change, from a list of red crosses to a list of green checks.
One thing that hasn’t been mentioned in the article is l, if you’re doing online validation (on change, on blur, and on focus), if the submit button of the form should be disabled as long as the form isn’t completely valid.
- Cthulhu_ 5y agoI don't think the bulletpoint list of requirements is that relevant anymore; instead, I'd give a live updating password strength indicator and reject anything "weak" or "medium". That way, the user can themselves decide on symbols and letters or length. A check on commonly used passwords should also be included of course.
- verinus 5y agoWell I think if you have such rules in place you should always indicate what rules are not satisfied by a password- and not only after hitting submit!
- andrewstuart2 5y agoAgreed. And even if you're only going to judge the strength, at least show what the user can continue to do or has already done to strengthen their password.
- kwyjobojoe 5y agoI wrote documentation for software that replaced set rules with a library that would determine the 'strength' of a password and only accept strong passwords. My feedback was 'this is bullshit, I've have 40 passwords rejected and I don't know why. How is the non-technical user supposed to pick a password when the rules and tests are secret and the doc person themselves can't use it?'