Re: Text_Password: [Fwd: Re: [phpsec] PHP-Based User Authentication Security]
| From: | Martin Jansen | Date: | Mon, 24 Jan 2005 10:35:52 +0000 |
| Subject: | Re: Text_Password: [Fwd: Re: [phpsec] PHP-Based User Authentication Security] | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-35689@lists.php.net to get a copy of this message | ||
On Mon Jan 24, 2005 at 12:1210AM +0100, Lukas Smith wrote:
>> -------- Original Message --------
>> Subject: Re: [phpsec] PHP-Based User Authentication Security
>>
>> As developers, we should not just pawn off this responsibility to our
>> users. Sure, if they choose a weak password, it's there own fault. I
>>
>> Right, but there are simple rules to force the users to not use
>> passwords that are too obvious, like passwords that are equal to user
>> names or contain parts of their names or birth dates.
>
> maybe it would be a good idea to add such features to Text_Password?
This is in the works and with a bit of luck it will be included in the
next release of Text_Password.
- Martin