New Project: PasswordStandards.com
By Daniel Miessler on November 12th, 2007: Tagged as Business | Community | Information Security | Security

I’ve just registered the domain of passwordstandards.com as part of a new project. The goal of the endeavor is to call attention to online services that don’t allow their users to select decently strong passwords. This is especially crucial for services that are financial in nature or maintain other types of sensitive information.
Project Clarification
First things first — the main focus of this site is to allow users to select strong passwords, not to disallow them from selecting weak ones. Prohibiting weak passwords is important as well but will not be the focus of the project.
Basic Goals
- Maintain a list of offenders and regularly “encourage” those on the list to improve
- Have a few categories for the sites listed, e.g. financial, personal, etc.
- For each site show the existing, weak standard that they support, e.g. no capitalization, or no special characters
- Provide an interface for the community to submit sites for addition or deletion
The Mission Statement
So let’s agree on a general project statement. Here’s what I’m thinking:
Any online service that requires a login should allow security-conscious users to select strong passwords. If security is not a concern for your service then don’t require a password. If it is a concern then allow users to create a decent one.
Please allow at least the following:
- Ten (10) total characters in length
- Lowercase and uppercase letters
- Numbers (0-9)
- Basic special characters (to be agreed upon)
Thoughts?
Related Content
- The List Of Shame: Websites That Don’t Allow Special Characters In Their Passwords
- Security: Implementing A Secure And Usable Internet Password Scheme
- Lame Online Password Logic
- Password Reset Mechanisms: The Online Security Threat Nobody’s Talking About
- From Password Reset Mechanisms to OpenID: A Brief Discussion of Online Password Security