-
-
Notifications
You must be signed in to change notification settings - Fork 296
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
update readme to not be plain and simple shaming #219
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -15,6 +15,21 @@ See other sites for the formatting and follow these rules: | |
- Include at least one screenshot. | ||
- Keep the sites in alphabetical order. | ||
|
||
Ok, I'm on that list, what should I do ? | ||
---------------------------------------- | ||
|
||
We recommend you that in the future you refer to the OWASP (Open Web Application Security Project) | ||
before implementing or specifying web applications. | ||
|
||
For example the current set of recommendation, and the rationals on "why" for password rules are here: | ||
https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Authentication_Cheat_Sheet.md | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Can we make this a more user friendly clickable hyperlink? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Does it also make sense to reference the actual revised NIST guidelines, here: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecret Afterall, it was versions of those guidelines in the past that gave s the nightmare that we see today... |
||
|
||
As of 2019, the rules are basically: | ||
|
||
* at least 8 characters long | ||
* never expires | ||
* better to check against a list of leaked/common passwords like https://haveibeenpwned.com/API/v3#PwnedPasswords | ||
|
||
Sites | ||
----- | ||
----------------- | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.