Skip to content

Comment on Ask HN: Is there a good reason for disallowing some characters from a password?

Comments

let me quote NIST Special Publication 800-63B: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecret

Verifiers SHALL require subscriber-chosen memorized secrets to be at least 8 characters in length. Verifiers SHOULD permit subscriber-chosen memorized secrets at least 64 characters in length. All printing ASCII [RFC 20] characters as well as the space character SHOULD be acceptable in memorized secrets. Unicode [ISO/ISC 10646] characters SHOULD be accepted as well.
AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.