You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It might also be worthwhile to implement a mechanism that adjusts the character set based on the specified length. For instance, if the user requests a password length of less than 8 but still wants complexity, we could limit the character set to alphanumeric only or even just lowercase letters. This could help maintain a balance between security and usability, especially for shorter passwords. Would this type of dynamic adjustment be something you'd want to include?
Reducing the character set (such as restricting short passwords to alphanumeric or lowercase only) actually makes short passwords much less secure. Short passwords already have low entropy, so limiting the pool of characters significantly reduces the search space for brute-force attacks.
Instead, short passwords need more complexity, not less. A better approach is:
Require a minimum password length (e.g., at least 8 or 12 characters).
Ensure at least one character from each required category (uppercase, lowercase, digits, special characters) is guaranteed.
Use the secrets module instead of random for cryptographically secure random generation.
generate_password function to allow users to specify the desired complexity, with flags for including/excluding digits and punctuation. This would provide more flexibility for users who may have varying security requirements or restrictions
import string, random
def generate_password(length=8):
chars = string.ascii_letters + string.digits + string.punctuation
return ''.join(random.choice(chars) for _ in range(length))
print(f"Пароль: {generate_password(10)}")