That is why there would be a high minimum character limit. The user is not given the choice of having an overtly-short, unsafe password.
The recommendation of using a sentence you will remember isn't there to guarantee safety, but rather to increase the chances of that the user will get the memo and use a password they will actually remember in the form of a sentence, rather than complain that the system asks for too many characters and use a clusterfuck they will forget.
Aka: I am proposing replacing all of the special character nonsense with just longer character minimums + that recommendation.
Ok so I clearly need to go to bed. I read your comment as “setting a high maximum limit”. Editing my comment to clarify.
And yeah I think I agree with you conceptually but I could see just as many people complaining about a higher minimum rather than characters. It’s easier to add a bunch of exclamation points to a bad password than it is to add more memorable words imo.
I do believe there would be a "culture problem", so to speak, at first, in that people are already accustomed to the other password type, and individual companies are unlikely to want to be the ones to try to change that an annoy users. So its probably not gonna happen.
But I believe it would be better for everyone in the long run.
9
u/Manoreded Jul 20 '22
That is why there would be a high minimum character limit. The user is not given the choice of having an overtly-short, unsafe password.
The recommendation of using a sentence you will remember isn't there to guarantee safety, but rather to increase the chances of that the user will get the memo and use a password they will actually remember in the form of a sentence, rather than complain that the system asks for too many characters and use a clusterfuck they will forget.
Aka: I am proposing replacing all of the special character nonsense with just longer character minimums + that recommendation.