[wp-trac] [WordPress Trac] #32261: Security: Wordpress Admin/Backend: No Passwordlength is enforced = Big Security Risk

WordPress Trac noreply at wordpress.org
Wed May 6 00:50:09 UTC 2015


#32261: Security: Wordpress Admin/Backend: No Passwordlength is enforced = Big
Security Risk
------------------------------+------------------------------
 Reporter:  iamwordimpressed  |       Owner:
     Type:  defect (bug)      |      Status:  new
 Priority:  normal            |   Milestone:  Awaiting Review
Component:  Security          |     Version:  4.2.1
 Severity:  normal            |  Resolution:
 Keywords:  close             |     Focuses:
------------------------------+------------------------------

Comment (by iamwordimpressed):

 In my opinion this is a completely wrong way of thinking.

 Good software would do it this way:

 - A Backend-Option for Admin, that allows some basic configuration of
 Password-Strength and that is set to a reasonable goot security level by
 default (security by design). And a '''very easy way (1 Click) to disable
 or to configure''' it to less secure levels. Yes you are right 1% of the
 wesites need a less secure WP. They then can configure it easyly with
 these options.

 Bad Software does it like this:
 - No Security at all and 99% of the Admins even dont know that they have a
 huge security risk (this is nowhere documented, thats the problem(!!!)
 Happy Hacking.

 Yes thanks for the link, I had googled it before posting. And I had to
 lough loud: Wordpress is rund on 60.000.000 (?) Websites and the Plugin
 has 7.000 active installs. Wow, q.e.d.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/32261#comment:2>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list