•  
      request #10500 Remove default password composition rule
    Infos
    #10500
    Thomas Gerbet (tgerbet)
    2017-07-31 08:41
    2017-07-26 18:02
    10742
    Details
    Remove default password composition rule
    Tuleap comes with a default composition rule for password forcing the users to have at least a number in their password.

    These composition rules are now proven to be counter productive, users do not make stronger password because of them and they are annoying (yes, my password of 64 random letters is more secure than my password composed of 8 letters and digits).

    References:
    NIST’s Digital Identity Guidelines: https://www.nist.gov/itl/tig/special-publication-800-63-3
    Microsoft Password Guidance: https://www.microsoft.com/en-us/research/wp-content/uploads/2016/06/Microsoft_Password_Guidance-1.pdf [PDF]
    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2017-07-27
    Attachments
    Empty
    References

    Follow-ups