Here is the text of the NIST sp800-63b Digital Identity Guidelines.

You are viewing a single thread.
View all comments
28 points

Interesting that unicode support is suggested. Emoji passwords could be fun.

permalink
report
reply

Characters are characters. The system I just wrote will accept anything, because the first thing I do with it is hash it. If you want to make your password:

░▒▓█ ʥ۞ݔݯݲݸݴݺ '; drop table users; 🤣💩ʩ █▓▒░

Then go for it. More power to you for typing that out or, more likely, letting your password manager remember it. Make your password as entropic as you can manage, I don’t care how you arrive there.

permalink
report
parent
reply
16 points

Yup. All I care is that your password isn’t the entire works of Shakespeare or something like that. A couple hundred characters/bytes? You do you.

What really bothers me is when a website says something like: must have a special character, except these ones (proceeds to list everything except @ and !). And then the next one has the same rule, but different exceptions.

Passwords should be treated as a black box, just read it as bytes and throw it into the hash algorithm. You want to somehow enter a nyan cat? Be my guest, no guarantee the input box will accept it though.

permalink
report
parent
reply
12 points

also: “password is too long, max password length is 12 digits”

Why… like, sure, cap it at 256 or something reasonable. but ive run into as low as 9 digits.

permalink
report
parent
reply
4 points

Haha, and I smiled when I looking for the single quote in your password and sure it is there👍👍

permalink
report
parent
reply
9 points

my password is just 20 gigabytes of poop emojis.

permalink
report
parent
reply
5 points

Multiple languages.

permalink
report
parent
reply
4 points

Yeah, multiple languages or even putting an ê or something in an English password to mix things up. It makes perfect sense to allow.

It’s a good thing they require each codepoint to be treated as one character for the length limit, since “🤔🤣” is 8 bytes on its own, but the unicode prefix is trivial to guess.

permalink
report
parent
reply
3 points

Emoji passwords made me think of the Lotus Notes password prompt with their little images that changed as I typed (which never really made sense to me).

Yes, I’m old…

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 18K

    Monthly active users

  • 5.2K

    Posts

  • 96K

    Comments