Hacker News new | ask | show | jobs
by lmm 2376 days ago
> You're probably right theoretically, but people tend to choose really weak password if they can choose anything.

Not in my experience. If I can choose anything I'll write a decent-length phrase. If I'm forced to use numbers and symbols I'll make the shortest thing I can.

Certainly there's no reason to reject a 20+ letter all-lowercase password. Apply your capital/number/symbol rules to passwords shorter than 16 characters if you must.

1 comments

This is a really old-timey snipe, but...

You are not a typical computer user. The typical computer user is Karen from accounting, and Bob from HR.