GSA / GSA/Crowdsource-Testing-FTC-IdentityTheft.gov_11-2015
Password strength. Rule not clear
- Dominant language
- No language data
- Stars
- 0
- Forks
- 2
- PR merge metrics
- No merged PRs in 30d
Description
When I was creating my test account I noticed a character set rule that wasnt explained to the user.
If I typed in a pattern of special characters that are next to each other in a QWERTY layout on the 4th character the meter goes to 0 and fails the password creation.
Example
!@#$ (1-2-3-4) with shift selected fails and goes to 0.
!@#% (1-2-3-5) with shift selected and it works successfully
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reproducing the password-meter behavior with the two examples in the issue. Locate the password-strength validation and its user-facing rule or message; the issue is done when the character-set rule is clearly explained and the intended handling of the failing pattern is confirmed.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100