fedora-infra / fas

Fedora Account System
https://admin.fedoraproject.org/accounts
GNU General Public License v2.0
40 stars 50 forks source link

Please revisit FAS password rules #57

Closed comzeradd closed 3 years ago

comzeradd commented 10 years ago

The requirements for a FAS password are mad, offering no real sense of security. It's better to force long passwords, than forcing into deprecated schemes with special characters, numbers and uppercase letters.

Reference: https://pbs.twimg.com/media/BhkZoPrCYAEF8ww.png:large http://xkcd.com/936/

pypingou commented 10 years ago

well, we cut the apple in the middle, you can have a long password when only lowercase characters or a shorter password with a mix of lower/upper chars/number and special chars. Up to you :)

comzeradd commented 10 years ago

Yes, indeed. But the UX outcome is far from great :) Maybe the error message needs some re-arrangement to look less scary.

abadger commented 10 years ago
Please suggest a better error message and we'll see about merging it.
comzeradd commented 10 years ago

I think a good start would be to break it down in bullets, just like it's been displayed in the "change password" form. It would be much easier to read and understand the different options.

cydrobolt commented 10 years ago

@comzeradd Still working on a better error message? I can fix it if no one else is working on it.

comzeradd commented 10 years ago

Not very familiar with turbogears, so never found the time to initiate a local instance and test things. If you can fix this please go ahead :)

ryanlerch commented 3 years ago

Closing this issue as the FAS project is now archived, not actively developed, and unmaintained.

FAS was replaced in March 2021 by Fedora Accounts (https://accounts.fedoraproject.org).

If this issue is a Feature Request that might be beneficial to Fedora Accounts, please refile it against Noggin