Hacker News new | ask | show | jobs
by OedipusRex 3551 days ago
Who would enforce it on any website? The US government, or W3C, or IANA? Everyone talks about a free and open web and no one wants someone poking around behind the scenes. I don't trust anyone to enforce password rules for fear of exploitation. The user is responsible for their password security and it should stop there.

That being said, Yahoo should have force reset passwords.

1 comments

> The user is responsible for their password security and it should stop there.

That would be true if the user created, stored, authenticated the password himself.