2 ms·
I'm all in favor of making the passwords as secure as possible for your users, but I hate it when I'm dictated how my password has to look. For less than critic
by dirkdeman 15y ago
I'm all in favor of making the passwords as secure as possible for your users, but I hate it when I'm dictated how my password has to look. For less than critical accounts I always use the same password, which is easy to remember to me. If any account is hacked, it’s not a disaster. I just hate it when I sign up for something the website throws back ‘your password should be at least 8 charachters long, contain one of the following characters: @!#$ etc. etc.’. From a usability point of view this is a nightmare, and it will cost you users.
In the end, the user is responsible for choosing a secure password. You can only direct.
On a side note: the 'unbreakable' Enigma cypher was cracked (partly) because the German re-used part of the encrypting key, for example, one operator often used the name of his girlfriend as a key. These easy to distuinguish words were called cillies (see http://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma#Operating_shortcomings http://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma#Ope... ).
My point is that you should do everything possible to encrypt the passwords of your users without sacrificing usability.