Security: stronger password requirements

Bug #457357 reported by root
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
psiphon
Confirmed
Unknown
Unassigned

Bug Description

* Recommend at least 6 characters, plus mix of classes.
* Could have stronger requirements for more privileged users (Admin, etc.) -- would need some tricky logic in case where user role changes.
* Other common practices:
* User name not a substring
* Dictionary checks (excepting passphrases)
* Expiry & history?
* There's a lot of good info here: http://en.wikipedia.org/wiki/Password_strength. Studies indicate that user's password strength depends on the instructions they are given. Again, this is especially important for higher privileged users.

Tags: category3
Adam P (adam+)
description: updated
Adam P (adam+)
Changed in psiphon:
status: New → Confirmed
Rod (rod-psiphon)
visibility: private → public
Rod (rod-psiphon)
tags: added: category3
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.