I hate password rules
posted Thu 16 Mar 2017 by Michael Galloy under ProgrammingExcellent rundown of all the horrible rules that organizations impose on your passwords:
- They donāt work.
- They heavily penalize your ideal audience, people that use real random password generators. Hey guess what, that password randomly didnāt have a number or symbol in it. I just double checked my math textbook, and yep, itās possible. Iām pretty sure.
- They frustrate average users, who then become uncooperative and use ācreativeā workarounds that make their passwords less secure.<br />> * They are often wrong, in the sense that the rules chosen are grossly incomplete and/or insane, per the many shaming links Iāve shared above.
- Seriously, for the love of God, stop with this arbitrary password rule nonsense already. If you wonāt take my word for it, read this 2016 NIST password rules recommendation. Itās right there, āno composition rulesā. However, I do see one error, it should have said āno bullshit composition rulesā.
My personal pet peeve is forced expiration for no reason. NIST is developing guidelines.
