MyBB Community Forums

Full Version: Password Length on Install
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
When I installed the latest code from the github repo, I realized that there is not a minimum length requirement set for the install.

I was successfully able to install with the password "admin", which is 5 characters. However, when changing your password in the UCP or in the ACP, you have to have a minimum password length of 6 characters. I think minimum password length should be made consistent across the system, including the install.

Thanks for considering.
I think it was this way for MyBB 1.6 too. I think the, "Require a complex password?" should be on by default and checked upon installation for admin.
The admin should know to use a strong password...
It's not our problem if a dumb admin chooses a dumb password. Although we should encourage a strong password everywhere (i.e. installer, Admin CP edit user, User CP, password reset). Perhaps we could add a JavaScript strength checker...
Of course it isn't your fault or responsibility. I just think it's weird that the minimum password lengths are not the same and would consider that a bug. If you can't choose a certain password normally, you shouldn't be able to choose it on install.
I'd leave it as it is. It's a difference whether an admin needs to set a password or a user registers. IIRC it was already decided as someone else mentioned it too. I'd hate it when I need to set strong passwords on every test installation...
My comment is solely about the length of the password. I don't consider 6 characters to be a strong password, but fair enough. Just wanted to bring it up.
I'm rejecting this, I hope you understand our point of view. I understand yours - though I think we're right.