I got this message again this morning and I am so sick of it!
Only 16 chars? O RLY? What if my dog's name is more than 16 chars long?
Further investigation of the JS source reveals that other error messages include:
Password can only contain letters and numbers
I am always talking to people about password policy and no wonder people are confused. So much good guidance out there is buried under so much rubbish.
Compare this to the other user experience that is becoming more common:
Much better! There was a time when it would be appropriate to explain why the second case is better... but in this day and age it should be obvious. It is all about coercing people to do good passwords until they are made obsolete in the future.
Since Version 1.0.60731.0 of the ASP.NET AJAX Control Toolkit there has been a quite good Password Strength control available to the ASP.NET platform. Everyone else (like my first, deliberately anonymous example) can just Google it! There are plenty of samples available.
One that I liked was at Gerd Riesselmann's blog, where he shares (GPL) a simple example suitable for learning how this is done.
What do you think? Is there any excuse for giving poor password guidance in 2007?
Powered by: newtelligence dasBlog 2.0.7226.0
Disclaimer The opinions expressed herein are my own personal opinions and do not represent my employer's view in anyway.
© Copyright 2008, James Green
E-mail