How do you enforce strong passwords?

前端 未结 4 1880
不知归路
不知归路 2021-02-14 23:55

There are many techniques to enforce strong passwords on website:

  • Requesting that passwords pass a regex of varying complexity
  • Setting the password autono
4条回答
  •  刺人心
    刺人心 (楼主)
    2021-02-15 00:35

    Why enforce it?

    I found that a "password strength meter" (a bar indicating password strength as you type) is usually a good non-intrusive measure. It makes those who care about security to have a guilty conscience about password weakness, yet does not frustrate those who do not care as much.

    Also, there is an insightful essay on why periodic password change policy is a bad idea with today's threat model.

提交回复
热议问题