4 ms·
We use zxcvbn and allowing only good passwords (score >2) is already too hard for many people to figure out a usable password.
by samastur 4y ago
We use zxcvbn and allowing only good passwords (score >2) is already too hard for many people to figure out a usable password.
- atoav 4y agoDid you consider adding password suggestions? I do this. Generate 10 passwords and make them clickable.
- hdjjhhvvhga 4y agoThis is the only thing that makes sense. Asking the user to create a password that is complex enough is just a waste of their time.
- atoav 4y agoI would not go so far and say this is the only thing that makes sense. It made sense for my service, because it runs in a context where people can trust me to not copy the password suggestion and store the clear text. But every application context is different, so maybe offering a clear text password for your users to choose might ring the wrong bell in yours.
- Tostino 4y agoThis is too real. I wrote a java port of it to use with my SaaS, Nbvcxz. I had attended many in-person and webinar training sessions with our customers, and inevitability you'd have someone who was just unable to get past creating a password that didn't contain their name and birthday, or part of their email address, or the company name...all of which are added to a personalized exclusion dictionary. These are all internal users at large CPG companies in sales or accounting. I don't understand how so many people who have to work with software all day cannot figure out passwords and login flows.