# 有没有办法使密码要求变得更简单？

**URL:** https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808
**Category:** Support
**Created:** [2016 年8 月 18 日 13:57 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808 "2016-08-18T13:57:11Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### 作者： ![Donald\_Swofford](https://avatars.discourse-cdn.com/v4/letter/d/bc8723/32.png) [@Donald\_Swofford](https://meta.discourse.org/u/Donald_Swofford)
#### 发布日期： [2016 年8 月 18 日 13:57 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/1 "2016-08-18T13:57:11Z")

</div>

Is there a way to make the password requirements more simple? It requires like 15 digits? thats tooo many! like 6 should be enough imho for my site.

---

<div class="post-metadata">

### 作者： ![cpradio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cpradio/32/4970_2.png) [@cpradio](https://meta.discourse.org/u/cpradio)
#### 发布日期： [2016 年8 月 18 日 14:01 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/2 "2016-08-18T14:01:27Z")

</div>

15 is for admins, 10 is the default for regular users. Both are configurable in the Admin \> Settings area, search for `password`

---

<div class="post-metadata">

### 作者： ![Donald\_Swofford](https://avatars.discourse-cdn.com/v4/letter/d/bc8723/32.png) [@Donald\_Swofford](https://meta.discourse.org/u/Donald_Swofford)
#### 发布日期： [2016 年8 月 18 日 14:07 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/3 "2016-08-18T14:07:06Z")

</div>

Whoops found it under Admin\>Settings\>Users. Should I delete this question? Sorry I had searched but didn’t see it.

---

<div class="post-metadata">

### 作者： ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### 发布日期： [2016 年8 月 18 日 14:28 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/4 "2016-08-18T14:28:03Z")

</div>

If your site will be connected to the internet, then 6 characters is almost certainly not enough. If it requires registration,so crackers do not know usernames, that could reduce the need for complexity, but, it’s still not a good idea.

See, for example

> **[Your Password is Too Damn Short](https://blog.codinghorror.com/your-password-is-too-damn-short/)**
>
> I’m a little tired of writing about passwords. But like taxes, email, and pinkeye, they’re not going away any time soon. Here’s what I know to be true, and backed up by plenty of empirical data:
> 
> \* No matter what you tell them, users will always...

---

<div class="post-metadata">

### 作者： ![Donald\_Swofford](https://avatars.discourse-cdn.com/v4/letter/d/bc8723/32.png) [@Donald\_Swofford](https://meta.discourse.org/u/Donald_Swofford)
#### 发布日期： [2016 年8 月 18 日 14:37 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/5 "2016-08-18T14:37:21Z")

</div>

curses! Ill put the default back. But doesnt gmail even allow “aaaaaaaa”?  
[Gmail Password Requirements](http://www.passwordpit.com/gmail-password-requirements/)

---

<div class="post-metadata">

### 作者： ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### 发布日期： [2016 年8 月 18 日 14:48 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/6 "2016-08-18T14:48:19Z")

</div>

If you want easy login and sign in, set up social logins, users can authenticate with Facebook, Google, Twitter, etc.

No password is better than a bad password 😄

---

<div class="post-metadata">

### 作者： ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### 发布日期： [2016 年8 月 18 日 14:55 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/7 "2016-08-18T14:55:03Z")

</div>

> [@Donald\_Swofford](#):
>
> Whoops found it under Admin\>Settings\>Users. Should I delete this question?

Well, if you couldn’t find it among all the settings, someone else won’t either.

Also, the discussion about password complexity is likely important for others as well.

---

<div class="post-metadata">

### 作者： ![watchmanmonitor](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/watchmanmonitor/32/430970_2.png) [@watchmanmonitor](https://meta.discourse.org/u/watchmanmonitor)
#### 发布日期： [2016 年8 月 18 日 15:02 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/8 "2016-08-18T15:02:49Z")

</div>

> [@Donald\_Swofford](#):
>
> Should I delete this question? Sorry I had searched but didn’t see it.

It’s good to have questions asked and answered here on meta.

Marking the best answer as the Solution would also be helpful.

---

<div class="post-metadata">

### 作者： ![Mittineague](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mittineague/32/114259_2.png) [@Mittineague](https://meta.discourse.org/u/Mittineague)
#### 发布日期： [2016 年8 月 18 日 15:20 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/9 "2016-08-18T15:20:04Z")

</div>

There is also a “common password” Setting.

For example, on my localhost development Discourse I have that disabled so I can use “password” as a password and not need to remember a mess of different passwords for the test accounts.

But IMHO on a real live site it would be a poor idea to allow “password”, “admin”, “aaaaaaaa” etc.

If you look in /lib/10-char-common-passwords.txt there is a list of 2344 such passwords.

---

<div class="post-metadata">

### 作者： ![gdpelican](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/gdpelican/32/81308_2.png) [@gdpelican](https://meta.discourse.org/u/gdpelican)
#### 发布日期： [2016 年8 月 18 日 15:28 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/10 "2016-08-18T15:28:50Z")

</div>

Despite all of the evidence presented that passwords need to be long, I’m still often annoyed by the 10 character limit (especially on mobile, where typing 10 characters into a password box is a bit of a chore).

SSO seems like a good option; I wonder if the ‘Sign in via email’ pattern that slack uses might be useful as well?

- Click ‘send me an email to sign in’
- I get an email with an expiring (5 minutes?) link in it
- If I click on that link, it logs me in and takes me to the front page.

---

<div class="post-metadata">

### 作者： ![elijah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elijah/32/104055_2.png) [@elijah](https://meta.discourse.org/u/elijah)
#### 发布日期： [2016 年8 月 18 日 16:26 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/11 "2016-08-18T16:26:41Z")

</div>

You are not me. I don’t go all xkcd with the horse and the staple and whatever, but I do find multi word pass ~~words~~ phrases work very well for me. Often they are word game things for me, rather than common phrases, related to the site or something at hand when creating it. For a cooking website, I might think of _Joy of Cooking_ and use “boy.of.Looking”. It annoys me when there are requirements other than length, because that can interfere with my method.

---

<div class="post-metadata">

### 作者： ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### 发布日期： [2016 年8 月 18 日 19:13 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/12 "2016-08-18T19:13:45Z")

</div>

Yes, but this is already possible with “forgot password”.

---

<div class="post-metadata">

### 作者： ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### 发布日期： [2016 年8 月 18 日 23:41 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/13 "2016-08-18T23:41:58Z")

</div>

> [@gdpelican](#):
>
> especially on mobile

I feel this pain sometimes, even with a password manager (which 99% of users do not have)

I would like to get around to adding a “1 time login token” for mobile.

- Click button
- We send email with 1 time login token
- User is logged on, on mobile

LOL, just realised you posted the same thing @gdpelican so yeah … I want this at some point 🙂

---

<div class="post-metadata">

### 作者： ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### 发布日期： [2016 年8 月 18 日 23:43 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/14 "2016-08-18T23:43:07Z")

</div>

> [@codinghorror](#):
>
> Yes, but this is already possible with “forgot password”.

not really, it burns your password, so that sucks.

---

<div class="post-metadata">

### 作者： ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### 发布日期： [2016 年8 月 18 日 23:43 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/15 "2016-08-18T23:43:37Z")

</div>

Not really, just press a bunch of keys on your keyboard to “generate” a new one. 😉

I do this on a few sites..

---

<div class="post-metadata">

### 作者： ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### 发布日期： [2016 年8 月 18 日 23:45 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/16 "2016-08-18T23:45:01Z")

</div>

You get a new auth token though, so all the other places you are logged into are now logged out ☹

Plus, you need to synchronize the password manager again.

---

<div class="post-metadata">

### 作者： ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### 发布日期： [2016 年8 月 18 日 23:45 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/17 "2016-08-18T23:45:38Z")

</div>

True, we have “safe” login mode set by default, so that would invalidate all logins across all sites.

My password manager is my browser, so it auto-syncs with no effort from me.

---

<div class="post-metadata">

### 作者： ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### 发布日期： [2018 年3 月 22 日 11:37 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/18 "2018-03-22T11:37:44Z")

</div>

> [@sam](#):
>
> I would like to get around to adding a “1 time login token” for mobile.

Ok, this is now shipping cc @gdpelican

 ![image](https://global.discourse-cdn.com/meta/original/3X/7/3/736d84e7141d53ed9bb4555f7f2d20d43b40100c.png)

I don’t see it triggering here on meta though, is it incompatible with social logins or something?

---

<div class="post-metadata">

### 作者： ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### 发布日期： [2018 年3 月 22 日 22:38 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/19 "2018-03-22T22:38:54Z")

</div>

> [@codinghorror](#):
>
> I don’t see it triggering here on meta though

We did not have `enable_local_logins_via_email` enabled, I just turned it on here. Feature is off by default.

Note, mobile is still only partially solved cause it does not work with the app yet but @j.jaffeux and me have a plan here.

---

<div class="post-metadata">

### 作者： ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### 发布日期： [2024 年6 月 8 日 12:37 UTC](https://meta.discourse.org/t/is-there-a-way-to-make-the-password-requirements-more-simple/48808/20 "2024-06-08T12:37:39Z")

</div>

此主题已在 2850 天后自动关闭。不再允许回复。
