|
|
|
|
|
by nordsieck
735 days ago
|
|
> Windows should be smart enough to know an empty password doesn't meet the password complexity requirements or is of length zero and not count it against the 'bad password count'. All that logic sounds like a recipe for introducing a side channel attack into the system. Much better to keep things simple. |
|