• 0 Posts
  • 37 Comments
Joined 3 months ago
cake
Cake day: July 22nd, 2024

help-circle



















  • Even in your example above, with only two letters, no numbers / special characters allowed, requiring a capital letter decreases the possibilities back to the original 676 possible passwords - not less.

    No it doesn’t. It reduces the possibilities to less than the 52x52 possibilities that would exist if you allowed all possible combinations of upper and lower case letters.

    You are confused because you only see the two options of enforcing or not allowing certain characters. All characters need to be allowed but none should be enforced. That maximizes the number of possible combinations.

    that passwords should all require certain complexity, but without broadcasting the password requirements publicly?

    No, because that’s still the same. An attacker can find out the rules by creating accounts and testing.