Password Rules Are Bullshit

General News

Summary

We can certainly debate whether "correct horse battery staple" is a viable password strategy or not, but the argument here is mostly that length matters. You may also be surprised, if you paste the above four Unicode emojis into your favorite login dialog (go ahead – try it), to discover that it … isnt in fact four characters. But expressing your love of entropy as terrible, idiosyncratic password rules … … is a spectacular failure of imagination in a world of Unicode and Emoji. Id like to offer the following common sense advice to my fellow developers: One rule is at least easy to remember, understand, and enforce. Yes, you must stop users from having comically bad passwords that equal their username, or or , but only as post-entry checks, not as rules that need to be explained in advance.

Classifications

industries
Automotive
applications
Web and Content Management

AskAI Classifications

Labels
SaaS Open Source Software Community Management Software

Linked Companies