Jump to content

password security


The Little Guy

Recommended Posts

Your best defense is only allowing a user to enter a password 3 times before it locks them out for 30 minutes.

 

Either way generally 8-12 characters with a mixture of upper/lower numbers and at least 1 special character IE:

 

m0unT4inM4N!

 

Would take a long time to break.

Link to comment
https://forums.phpfreaks.com/topic/45363-password-security/#findComment-220280
Share on other sites

100 is supposed to be perfect or 100% Secure... What do you think?

 

Technically you cannot have a 100% secure password. It is just a matter of time and computational power before it can be cracked.

 

You could start with a basic score, then add points to the score based the the following things:

- length

- contains a-z?

- contains A-Z?

- contains 0-9?

- contains special characters (all other than a-zA-Z0-9)?

- contains words in a dictionary (deduct points)?

- contains reversed words in a dictionary (deduct points)?

- contains patterns on keyboard - e.g. qwerty (deduct points)?

Link to comment
https://forums.phpfreaks.com/topic/45363-password-security/#findComment-220433
Share on other sites

Why bother? It's not your problem.

 

If you end up telling someone their password is 100% amazing, then it is cracked 20 minutes later, can they sue you for one million US bucks?

 

It's up to the user to type in something secure. What they type is nothing to do with you.

 

monk.e.boy

Link to comment
https://forums.phpfreaks.com/topic/45363-password-security/#findComment-220451
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.