Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Lars Wirzenius
@liw@toot.liw.fi  ·  activity timestamp 3 weeks ago

I'm tired of web sites inflicting known-bad rules on passwords. Like what characters are required, or minimum length.

https://pages.nist.gov/800-63-4/sp800-63b/passwords/
https://www.schneier.com/blog/archives/2024/09/nist-recommends-some-common-sense-password-rules.html
https://tuta.com/blog/minimum-password-length

TL;DR: don't require specific classes of characters, require at least 15 characters.

I'd go for a minimum length of at least 16, myself. Brute force guessing is a thing and is dealt with by using longer passwords.

Any web site that doesn't follow these is just security incompetent.

#rant #passwords

  • Copy link
  • Flag this post
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.2.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login