How do you enforce strong passwords?

前端 未结 5 1339
我在风中等你
我在风中等你 2021-02-14 23:58

There are many techniques to enforce strong passwords on website:

  • Requesting that passwords pass a regex of varying complexity
  • Setting the password autono
5条回答
  •  无人共我
    2021-02-15 00:19

    Why enforce it?

    I found that a "password strength meter" (a bar indicating password strength as you type) is usually a good non-intrusive measure. It makes those who care about security to have a guilty conscience about password weakness, yet does not frustrate those who do not care as much.

    Also, there is an insightful essay on why periodic password change policy is a bad idea with today's threat model.

提交回复
热议问题