Lesspass: Allow Arbitrary Character Sets

Created on 21 Sep 2017  ·  5Comments  ·  Source: lesspass/lesspass

Some websites have dumb password rules. One particularly annoying practice is to only allow symbols from a very limited set such as % & _ ? # = -. It would be nice to be able to choose which characters go into passwords with more granularity to comply with these websites.

ux security

Most helpful comment

  • don't use those sites (imagine the quality of their system)

Heh, very true. Unfortunately the most common offenders I've noticed are banks, government sites, etc.

All 5 comments

Indeed, in cases such as this (though not many), you need to completely deactivate the option %!@ .

On the other hand it would be hard to memorize which characters have been enabled/disabled on which site. So this idea is good for those using the LessPass database.

That would require an additional option, or - if possible - the option %!@ given as now, with all characters activated by default and the chance to deactivate the ones not allowed manually (either singularly or maybe in groups).

The challenge would be to keep the interface clearly arranged.

Just brainstorming... good point anyway!

Hello,
This feature is linked with LessPass Database.
LessPass long term goal is to remove the need of LessPass Database.
So I see this feature as a step in the wrong direction.

We should encourage/force those sites to update their password policies with a hall of shame or something like that. By adding those features inside LessPass we put some effort on our side, instead of asking those sites to do the right job.

This option will be only interesting for sites which required a special char, but don't accept every special char. Mitigation:

  • don't use those sites (imagine the quality of their system)
  • send screenshot on social media
  • if you are forced to use those sites, just uncheck special char and append manually one common special char (!)

Good points, too, @guillaumevincent

  • don't use those sites (imagine the quality of their system)

Heh, very true. Unfortunately the most common offenders I've noticed are banks, government sites, etc.

I close this one, for all the reasons described above.
If you use LessPass Database:

  • increase the counter for those sites to find a password without excluded special chars.
  • remove special char and add the same one every time

None of the sites agree on the minimal symbols set. So even if we add an option with a small list of symbols, it may not solve the problem.

Was this page helpful?
0 / 5 - 0 ratings