4 ms·
That's really great feedback, thanks!
by ceolin 3y ago
That's really great feedback, thanks!
- lucb1e 3y agoFor the password thingy, please note that complexity requirements are explicitly not recommended. We're all used to them, but the knowledge that it's cargo cult hasn't spread through the community yet. I feel like I need to back my claim up: - USA NIST recommends¹ (Appendix A) to introduce a length requirement and deny using previously cracked passwords. These passwords should be obtained from publicly available lists. The reasons for not setting any requirements for complexity are set out in section A.3 of their publication. - The UK National Cyber Security Centre similarly recommends² password deny lists and calls for not using complexity requirements or regular password expiry - I think the german BSI or the Dutch NCSC or something also came around recently, but I can't find the link right now Another option to make the login flow smoother is just offering an email with a one-time 90-minute-valid (because greylisting) login link, as alternative to setting/entering a password (I personally prefer a password for frequently-used sites to not have to switch apps and pollute my inbox every time). ¹ https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S... ² https://www.ncsc.gov.uk/collection/passwords https://www.ncsc.gov.uk/collection/passwords