Comment on NIST proposes barring some of the most nonsensical password rules

<- View Parent
NotMyOldRedditName@lemmy.world ⁨1⁩ ⁨month⁩ ago

I think it’s pretty idiotic to

Verifiers and CSPs SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords.

They might mean well, but the reason we require a special character and number is to ensure the amount of possible characters are increased.

If a website doesn’t enforce it, people are just going to do a password like password

password is a totally valid password under this rule. Any 8 letter word is valid. hopsital for example.

These passwords can be cracked in seconds, and have their hashes checked for in leaks in no time.

source
Sort:hotnewtop