r/mildlyinfuriating Mar 08 '16

Overdone Fuck it, hackers win.

Post image
14.6k Upvotes

992 comments sorted by

View all comments

Show parent comments

200

u/Dyschord Mar 08 '16

Came here to ask this exact question. If you know the constraints on the password string, it should be much easier to brute force 8 characters.

Broad requirements like password length is fine. Requiring a range of characters, letters, and special characters would make a brute force attack harder. Requirements like no consecutive letters or repeated letters seems to weaken the password. Why would this be a good idea?

141

u/Grintor Mar 08 '16

They don't want 30% of people's password to be abcdef#1

Of course now those people's password is qwerty#1