[wp-trac] [WordPress Trac] #35817: Force users to set strong passwords

WordPress Trac noreply at wordpress.org
Thu Mar 23 10:31:47 UTC 2017


#35817: Force users to set strong passwords
----------------------------+------------------------------
 Reporter:  ericlewis       |       Owner:
     Type:  enhancement     |      Status:  new
 Priority:  normal          |   Milestone:  Awaiting Review
Component:  Administration  |     Version:
 Severity:  normal          |  Resolution:
 Keywords:  2nd-opinion     |     Focuses:  ui
----------------------------+------------------------------

Comment (by robdxw):

 Replying to [comment:9 lovingboth]:
 > Anyone who is an admin would be able to set the lowest acceptable
 password strength to whatever they like, via a simple dropdown / radio
 button menu in settings.
 >
 > '''Anyone who is NOT an admin should not get to choose what the lowest
 acceptable password strength is''', 'please confirm you want to use a
 rubbish password' prompt or not.
 >

 I tend to agree with this. By default, the current WordPress set up is:
 whoever sets the worst password controls how secure the site is. That
 seems fundamentally wrong - it should be the admin who controls how secure
 the site is, not anybody else. If the admin is happy for weak passwords to
 be in use, that's possibly a different matter, but they should at least
 have control over that decision.

 (And apologies for the duplicate ticket - I did search first, but
 obviously not well enough).

--
Ticket URL: <https://core.trac.wordpress.org/ticket/35817#comment:17>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list