3 ms·
This first version is really just a quick emulation of Apple's version. There are a few simple security improvements that could be made without reducing memorab
by stephencelis 18y ago
This first version is really just a quick emulation of Apple's version. There are a few simple security improvements that could be made without reducing memorability too much (dropping vowels, toggling case, swapping vowels for numbers that resemble them, randomizing where the symbol comes in, and perhaps making the number of symbols variable, as well), all of which I may put into the next version.
In the end, though, these passwords should be "secure enough" for most purposes, and should be generally more secure than the password of your average user. Using haddock to generate temporary passwords will hopefully just encourage users to be better about passwords in general.
- pingswept 18y agoYeah, a good point. For a lot of web services, the security doesn't need to be all that good. Also, it may be that giving users memorable passwords beats letting them make their own, whereupon many of them choose weak ones.