Re: PW validation (was: Re: Opinions wanted: article rating harmful?)
Sun, 23 Apr 2000 12:15:53 GMT
In lugnet.admin.general, Todd Lehman writes:
In lugnet.admin.general, Larry Pieniazek writes:
So are you going to enforce that people HAVE to set their passwords to
things that the validator feels don't suck,

That is its purpose.

But the validator doesn't find non-sucky passwords, it just finds the least
randomised - ie, it will pass something like:
4h(i,>$s&      but fail:

What's the point of allowing people to change from their highly randomised
default LUGNET password (because they have a hard time remembering it), if the
validator only allows something of greater randomisation?

IIRC at least one default LUGNET password failed? My LUGNET password which is
rather easy to remember.. passed with honours!

IMHO it is reasonable to impose a minimum limit of characters, impose an
alpha-numeric mix, maybe even make sure that it isn't just one word known to a
dictionary mixed with one number. But much more than that seems too
restrictive. There is also the counter-security risk - as people have to use
really complicated and random passwords, they tend to start writing them down
in places, password files etc.

Besides which, the longer it takes before users can change their passwords, the
greater chance that other people will stumble upon their LUGNET welcome pack,
which contains their password handily printed out :)

I'm not a security expert - just a user who would rather take the advice of a
password system but have ultimate personal responsibility over my password.


