|
|
|
|
|
by snowwrestler
4668 days ago
|
|
Why not just require your users to set a 4-word passphrase as their password? You'll capture more variations than you would working from a fixed 5,000 word dictionary, and your users can still choose to write the words down if they want--or they can use the password management features of their browsers if they want. Plus it would be more simple to build and maintain, which is a plus when it comes to security. |
|
If the system randomly chooses the four words then you force the user to exchange convenience for security.