I’ve just registered the domain of passwordstandards.com as part of a new project. The goal of the endeavor is to call attention to online services that don’t allow their users to select decently strong passwords. This is especially crucial for services that are financial in nature or maintain other types of sensitive information.
First things first — the main focus of this site is to allow users to select strong passwords, not to disallow them from selecting weak ones. Prohibiting weak passwords is important as well but will not be the focus of the project.
So let’s agree on a general project statement. Here’s what I’m thinking:
Any online service that requires a login should allow security-conscious users to select strong passwords. If security is not a concern for your service then don’t require a password. If it is a concern then allow users to create a decent one.
Please allow at least the following:
Thoughts?