Skip to content

Password strength calculation is too lax #494

@bdresser

Description

@bdresser

The ChoosePassword view has a password validation routine that attempts to enforce a certain degree of password strength, yet currently “abc123!” and “passw0rd!” will receive high strength scores. Since the password is used with browser-passworder to protect wallet keys, it’s likely that it’s worth brute forcing.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions