• halcyoncmdr@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 day ago

    Makes sense. Most compromises aren’t brute force attacks. Allow all the characters and any brute force that is attempted will have to assume they’re part of it.

    Removing required periodical changes means people are less likely to use the same password and just increment a number added to the end. A compromised password with a setup like that is still compromised, they can make an educated guess as to what the new number is based on when was compromised compared to now.