Does anyone know of any studies that weigh various password strength
requirements (e.g. minimum 8 characters, one capital letter, one number
of symbol) with users' ability to remember the passwords?
Or, on a more practical level, reports that track password strength
requirements vs. increased calls to support / password reset requests?
My client wants increased security, but I don't want the users to go
nuts. Trying to find a happy medium.
Also, have you ever had a website ask you to change your password (long
after you originally registered)?