3 ms·
I would strongly suggest not having password complexity or length requirements except for perhaps a minimum length of 16+. Anything else is additional user fru
by fire 4y ago
I would strongly suggest not having password complexity or length requirements except for perhaps a minimum length of 16+.
Anything else is additional user frustration and serves no real purpose given that you're presumably not storing passwords in plaintext in the year 2022.
- tonypham 4y agoThanks for your feedback. We'll consider making it a bit easier for users.
- fire 4y agocool; just to expand - since hashed passwords are all the same length in a db, there's no benefit for max length requirements, and providing character limitations gives attackers a blueprint for brute force attacks since they now know what characters they don't need to try. When your requirements are too strict, this can make hashes orders of magnitude faster to reverse. my personal stance is: if they can type it, it can be in a password
- tonypham 4y agoThe purpose of this is to prevent people from entering too simple passwords, like "theirname123". People still do it.
- fire 4y agoyeah, I find that it helps to have a password complexity gauge that shows the user their password is weak, but I still wouldn't stop them from using it ( except for minimum length )