And by setting minlength=12 and saying so on screen, UX but would be far better than being told «you can’t use that pwd Dave. Try again.»
So you're saying min=12 isn't good UX? :-) They wouldn't deploy the 300M blacklist either. They can afford to develop great controls.
-
-
I would do a risk analysis & threat models first.

-
My point is they do that all the time and clearly haven't concluded min=12 is a good idea. We don't have any data for that vs. blacklist.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.