[wp-trac] [WordPress Trac] #21737: Users should have to jump through hoops to set passwords of their choosing, and we should guard better against weak passwords

WordPress Trac noreply at wordpress.org
Wed Apr 17 19:14:58 UTC 2013


#21737: Users should have to jump through hoops to set passwords of their choosing,
and we should guard better against weak passwords
-----------------------------+------------------------------
 Reporter:  markjaquith      |       Owner:  westi
     Type:  feature request  |      Status:  accepted
 Priority:  normal           |   Milestone:  Awaiting Review
Component:  Security         |     Version:
 Severity:  normal           |  Resolution:
 Keywords:                   |
-----------------------------+------------------------------

Comment (by iandunn):

 When detecting a weak password, maybe it would be helpful to show a 'Learn
 more about Password Security' link next to the password strength meter or
 AYS. The link could display a modal containing a 3-5 minute video
 explaining the basics of choosing a good password, and recommending some
 best practices.

 In my opinion, one of the best practices should be using a password
 manager. They make it relatively easy and convenient to use strong
 passwords like ''cT,Mo&aFv;Ubn3t<S`6$WY{r:ek?g9Jx5w)'8 at CP''. They can be
 too complicated for beginners, but I think they're acceptable for the
 average user, especially when they integrate with the browser. The video
 could contain a step-by-step example of creating a password in a password
 manager, setting it in WordPress, and then logging in with it.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/21737#comment:25>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list