3 ms·
I agree with Steko that being case insensitive is not a big deal. If you force users to use randomly generated passwords, 12+ characters is safe whether case se
by qnr 13y ago
I agree with Steko that being case insensitive is not a big deal. If you force users to use randomly generated passwords, 12+ characters is safe whether case sensitive or not.
On the other hand, if users choose their passwords themselves... Well I made a quick script to analyze the RockYou leak of 32 million plaintext passwords:
91% of passwords are lowercase
5% are uppercase
3% are lowercase but begin with a capital letter
In other words, you can crack 99% of case sensitive passwords just by trying these 3 possibilities!