this post was submitted on 13 Dec 2023
923 points (97.8% liked)

Technology

60082 readers
3839 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] pirat@lemmy.world 7 points 1 year ago (1 children)

Limiting the length of a password (at least to something as low as 16 characters) sounds like an unnecessary, bad idea...

[–] ItsMeSpez@lemmy.world 4 points 1 year ago (1 children)

Placing any restrictions at all on what makes a valid password is an unnecessary, bad idea.

[–] pirat@lemmy.world 1 points 1 year ago* (last edited 1 year ago) (1 children)

I think I agree, but short passwords like "x", "69", "420", "abcd", "12345" etc. would take a very short time to brute-force... Is your take that even if these are allowed, it will make all other passwords of the site more secure, since it adds more possibilities to the list where nothing can be disregarded when trying to brute-force any other password?

[–] ItsMeSpez@lemmy.world 2 points 1 year ago

Yes that's exactly it. When you reduce the total space of possible passwords you are giving a brute force attack unnecessary hints to improve their attempts with. A weak password will always be a weak password, so single digits or obvious or popular patterns should be avoided, but this should be a matter of user education rather than a hard and fast rule for account creation.