Re: User Passwords: checking for unique chars

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Chris W. Parker wrote:
Alex Gemmell <mailto:agemmell@xxxxxxxxx>
    on Monday, February 14, 2005 7:24 AM said:


Hello!


Hi!

Bonjour!



########
# Code:
########


<beingfunnynotmean!>Do you also have a label on your computer that says
"Computer"?</beingfunnynotmean!>

No, but I do have a label that says "My Computer". Close enough, isn't it? ;)


Some questions (because I'm curious):

1. Why would you *not* allow special characters? Wouldn't allowing
special characters make the password stronger?

Agreed.


2. Why are you forcing the password to have all unique characters? I don't think I've ever read this as being a recommendation for strong passwords.

If anything unique characters would make a password less secure (from the perspective of a dictionary attack). Because once you know where the "A" is, and where the "B" is, etc. that only leaves you with the rest of the characters on the next cycle...




Chris.


--
Teach a man to fish...

NEW? | http://www.catb.org/~esr/faqs/smart-questions.html
STFA | http://marc.theaimsgroup.com/?l=php-general&w=2
STFM | http://www.php.net/manual/en/index.php
STFW | http://www.google.com/search?q=php
LAZY |
http://mycroft.mozdev.org/download.html?name=PHP&submitform=Find+search+plugins

Attachment: signature.asc
Description: OpenPGP digital signature


[Index of Archives]     [PHP Home]     [Apache Users]     [PHP on Windows]     [Kernel Newbies]     [PHP Install]     [PHP Classes]     [Pear]     [Postgresql]     [Postgresql PHP]     [PHP on Windows]     [PHP Database Programming]     [PHP SOAP]

  Powered by Linux