What is your favourite password rule?

  • Tar_Alcaran@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    8 months ago

    My favorite is “can’t be more than x% similar to the last 3 passwords”. Of course, you shouldn’t ever define what “similar” actually means.

    • jonne@infosec.pub
      link
      fedilink
      arrow-up
      2
      ·
      8 months ago

      And the only way to check that is by storing the previous passwords in a recoverable format.

      • JohnyRocket@discuss.tchncs.de
        link
        fedilink
        arrow-up
        0
        ·
        8 months ago

        I’m not sure but I think the previous password is mostly stored in an unrecoverable format and only upon changing your password, when you have to enter your previous one, does it store it in an unrecoverable format for 10x or so generations. Just a guess though for how AD might do it.

  • SkaveRat@discuss.tchncs.de
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    8 months ago

    Requirement: Needs special characters

    Not accepted for some reason: using ọ̵̑h̸̞̉ ̴̰͒g̴͛ͅõ̸̦ḓ̵͠ ̸̳͌w̵̡̛h̴̦͘ŷ̵̫