Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 922403
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 15, 20262026-05-15T19:01:28+00:00 2026-05-15T19:01:28+00:00

Is there something special about characters that should be allowed/not allowed in a password?

  • 0

Is there something special about characters that should be allowed/not allowed in a password?

I store the password in the db hashed/salted and use PDO to prevent against injection. Is what I’m doing enough? Recently I came across a system that disallowed a number of characters, don’t remember all of them, but one was the ampersand &. Were they doing it for anti-database injection reasons, or is there something else I’m missing? Should password characters be restricted to a certain set of characters or no need?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-15T19:01:28+00:00Added an answer on May 15, 2026 at 7:01 pm

    There is no technical reason to disallow any characters in a password. I guess in the case you describe, they would allow only alpha-numeric characters to avoid problems on the user’s side (say, by entering a character that isn’t available on keyboards in another country).

    Many providers and sites force users to choose very complex passwords containing a minimum number numbers and, sometimes, evenb special characters to prevent brute-forcing or dictionary attacks.

    I don’t think forcing people to choose a complex password is wise. Passwords you can’t remember, you will write down somewhere, which is often creating a much bigger security risk in real life.

    A simple rate limit in the login system (e.g. deny access for 15 minutes after 3 failed login attempts) takes the edge off the brute-forcing threat much more elegantly.

    One doesn’t have to agree 100% with it, but I found this provocative paper on the subject from Microsoft Research very interesting. So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users

    From the abstract:

    It is often suggested that users are hopelessly lazy and
    unmotivated on security questions. They choose weak
    passwords, ignore security warnings, and are oblivious
    to certificates errors. We argue that users’ rejection
    of the security advice they receive is entirely rational
    from an economic perspective. The advice offers to
    shield them from the direct costs of attacks, but burdens
    them with far greater indirect costs in the form of effort.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Is there something special about Safari for Windows and AJAX? In other words: Are
Is there something like InstallShield that I can use for free?
Is there something like a panel that I can use in a MFC application.
Is there something like python's interactive REPL mode, but for Java? So that I
Is there something available that could help me convert a XSD into SQL relational
Are there any pre-made scripts that I can use for PHP / MySQL to
I need to store much strings in RAM. But they do not contain special
Is there something like the Python descriptor protocol implemented in other languages? It seems
Is there something like Python's getattr() in C#? I would like to create a
is there something like a Quickfix in Eclipse IDE available in VisualStudio 2008? Thanks,

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.