Opened 2 years ago

Closed 2 years ago

Last modified 2 years ago

#23903 closed project (wontfix)

Enforce minimum master password complexity

Reported by: Dhiraj Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Hi Team,

Actual results:

There is no password complexity set for Master password in about:preferences#security , Because I was able to set my password like 123,123456,www, admin etc which is really common, apart from that we can use spaces as well in master password i was able to set space as my master password :/

Expected results:

Recommendation - Provide robust rules including upper lower letters, special characters etc..

Child Tickets

Change History (2)

comment:1 Changed 2 years ago by gk

Component: Core TorApplications/Tor Browser
Owner: set to tbb-team
Resolution: wontfix
Status: newclosed
Version: Tor: unspecified

I think this issue should be tackled in the Mozilla bug you opened (if at all): https://bugzilla.mozilla.org/show_bug.cgi?id=1408427. We'll pick things up from there. In general, there is a password quality meter that should help you not shooting yourself in the foot.

comment:2 Changed 2 years ago by atagar

https://xkcd.com/936/

Please do not require special characters or remove the ability to include spaces. There's better heuristics for password strength. :)

Note: See TracTickets for help on using tickets.