-
-
Notifications
You must be signed in to change notification settings - Fork 296
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
What is a dumb password rule? #367
Comments
There are countries with password rules :O ? I don't think we have some in Germany. There is a pretty good understand what a bad password is and insurances wont pay in these cases but I don't think they rely on a written law. Can you name a country that has such regulatory rules? |
France for example, but these are general "recommendations" from the data protection authority (CNIL) more than regulatory rules: Companies will follow the above recommendations, because in case of personal data loss they might be held responsible. But then is a mere minimal length for passwords considered to be a "dumb password rule"? |
In Germany:
|
I would define a dumb password rule as one that:
Password guidelines (aren't to my knowledge enforced, but are there as reference on what people should do)
|
Is this a duplicate of #80 ? |
I've added a note on the new site about page on the definition of a dumb rule. Which is, in fact, that there's no real definition here except that you'll probably know one when you see one. https://dumbpasswordrules.com/about/ |
The text was updated successfully, but these errors were encountered: