Skip to content

Password strength calculation is too lax #494

@bdresser

Description

@bdresser

The ChoosePassword view has a password validation routine that attempts to enforce a certain degree of password strength, yet currently “abc123!” and “passw0rd!” will receive high strength scores. Since the password is used with browser-passworder to protect wallet keys, it’s likely that it’s worth brute forcing.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions