Following OWASP 4.0 standards for password authentication

There has been a feature request along these lines: Password policy that supports passphrases / phrase passwords
It does also seem like there are a lot of organisations still using the more old school password composition rules though - Feature request: Password policy require 4 of 4 requirements
We’re all for the former, but an option to choose is probably the way to go.

1 Like