J4 Issue ?
avatar PhilETaylor
PhilETaylor
26 Apr 2017

The password strength bar is not fit for use

It gives an impression that the password provided is secure

A password of "admin" gives a 100% green bar....

screen shot 2017-04-26 at 13 09 27

avatar PhilETaylor PhilETaylor - open - 26 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 26 Apr 2017
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 26 Apr 2017
avatar franz-wohlkoenig franz-wohlkoenig - change - 26 Apr 2017
Category Installation
avatar dgt41
dgt41 - comment - 26 Apr 2017

Password accepted don't mean that the password is strong. You can change the settings to make it longer and requiring more special characters at the end the script is just manipulating these settings (blindly)...

avatar PhilETaylor
PhilETaylor - comment - 26 Apr 2017

So what is the point of this then if its not a complexity? if its just checking password length then can normal validation not do that...

At the moment its adding visual elements for the sake of it...

There simply is no need for a progress bar at all - unless its actually going to make user use more secure passwords

avatar dgt41
dgt41 - comment - 27 Apr 2017

@PhilETaylor the indicator is just indicating if the user is fulfilling the requirements of the site, set here:
screen shot 2017-04-27 at 12 40 44

In that context the script is not knowing if a password is strong or weak, it's just a visual help that the password is fulfilling the requirements of the site. Te initial settings are just password must be >4 characters long. Modifying these settings you can require numbers, capital letters, other symbols etc, and thus force to a more secure password

avatar PhilETaylor
PhilETaylor - comment - 27 Apr 2017

So I say again.

There is NO POINT in having this progress bar/strength meter in the INSTALLATION PROCESS OF JOOMLA when standard validation will do.

You might be able to configure the "widget" through Joomla admin, however thats not available until AFTER installation, and this issue is about the progress widget on the INSTALLATION process.

avatar dgt41
dgt41 - comment - 27 Apr 2017

@PhilETaylor I didn't realise you were referring to the installation process here, so yes then this makes sense

avatar PhilETaylor
PhilETaylor - comment - 27 Apr 2017

My screenshot was from the installation process :) I did forget to mention that :)

avatar franz-wohlkoenig franz-wohlkoenig - change - 1 May 2017
Status New Discussion
avatar brianteeman brianteeman - labeled - 25 Mar 2018
avatar PhilETaylor PhilETaylor - change - 15 May 2018
Title
[4.0] Password strength meter gives false impression
[4.0] Password strength meter in INSTALLER gives false impression
avatar PhilETaylor PhilETaylor - edited - 15 May 2018
avatar brianteeman brianteeman - change - 13 Jul 2018
Status Discussion Closed
Closed_Date 0000-00-00 00:00:00 2018-07-13 20:01:40
Closed_By brianteeman
Labels Added: J4 Issue
avatar brianteeman brianteeman - close - 13 Jul 2018
avatar brianteeman
brianteeman - comment - 13 Jul 2018

as the password strength validator is no longer present in the installer I am closing this

Add a Comment

Login with GitHub to post a comment