Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Enforcing password strength makes sense for a site which stores sensitive data. That said, some simple math suggests that length, not character complexity, should be required.

http://security.stackexchange.com/questions/6095/xkcd-936-sh...



I wonder if there are any sites that simply forbid passwords that are known to exist in rainbow tables.


I'd assume that's what they're talking about with the 'use blacklist'. It'd be easy enough to occasionally repopulate it with "obvious" or known-compromised passwords that turn up.

Likewise, I assume they're keeping that list semi-secure to avoid black-hats/kiddies getting their hands on a list of really good passwords to throw into their cracking engine ruleset.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: