We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

Clarify wording of "Allow dictionary words in passwords?" Security & Privacy option

Feature Requests

JCOGS Design's avatar
JCOGS Design
71 posts
6 years ago
JCOGS Design's avatar JCOGS Design

I think the wording of this option in CP is confusing.

Documentation states that “Disabling will make ‘dictionary attacks’ by hackers much more difficult.” - but for this to be so there needs to be a dictionary file (normally there isn’t). In the default install this option is disabled, suggesting that dictionary attacks are prevented; but since there is by default no dictionary.txt file installed, it actually does nothing. In the default case it is possible that people will think they have disabled dictionary passwords and actually have not.

A better option might be to change this option to be one where the user has to opt-in to dictionary protection (which is implicitly what is required now anyhow) - so option becomes “Prevent use of Dictionary Passwords” and the following entry (which gives name of dictionary file) could be required (and perhaps actively checked to ensure that the named dictionary was present in config folder) before allowing setting to be saved.

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.