Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 922403
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 15, 20262026-05-15T19:01:28+00:00 2026-05-15T19:01:28+00:00

Is there something special about characters that should be allowed/not allowed in a password?

  • 0

Is there something special about characters that should be allowed/not allowed in a password?

I store the password in the db hashed/salted and use PDO to prevent against injection. Is what I’m doing enough? Recently I came across a system that disallowed a number of characters, don’t remember all of them, but one was the ampersand &. Were they doing it for anti-database injection reasons, or is there something else I’m missing? Should password characters be restricted to a certain set of characters or no need?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-15T19:01:28+00:00Added an answer on May 15, 2026 at 7:01 pm

    There is no technical reason to disallow any characters in a password. I guess in the case you describe, they would allow only alpha-numeric characters to avoid problems on the user’s side (say, by entering a character that isn’t available on keyboards in another country).

    Many providers and sites force users to choose very complex passwords containing a minimum number numbers and, sometimes, evenb special characters to prevent brute-forcing or dictionary attacks.

    I don’t think forcing people to choose a complex password is wise. Passwords you can’t remember, you will write down somewhere, which is often creating a much bigger security risk in real life.

    A simple rate limit in the login system (e.g. deny access for 15 minutes after 3 failed login attempts) takes the edge off the brute-forcing threat much more elegantly.

    One doesn’t have to agree 100% with it, but I found this provocative paper on the subject from Microsoft Research very interesting. So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users

    From the abstract:

    It is often suggested that users are hopelessly lazy and
    unmotivated on security questions. They choose weak
    passwords, ignore security warnings, and are oblivious
    to certificates errors. We argue that users’ rejection
    of the security advice they receive is entirely rational
    from an economic perspective. The advice offers to
    shield them from the direct costs of attacks, but burdens
    them with far greater indirect costs in the form of effort.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

in a .net web app is there something special about .aspx pages and the
Is there something special about Safari for Windows and AJAX? In other words: Are
Is there something in EF 4.1 that allows for a reconnect to a database
Is there something new about row-level security in SQL Server 2012? In 2008 and
Is there something in the Android developer guidelines that disuades developers from providing the
Is there something like SESSION in Windows application? I want to store a few
Are there any pre-made scripts that I can use for PHP / MySQL to
I need to store much strings in RAM. But they do not contain special
Is there something equivalent to OmniCppComplete for java in vim ? I know of
Is there something akin to the .NET xsd.exe for java - generating classes from

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.