If don't have a length restriction, the majority of people will still use more than that and he has to look.Sure, but security should work for everyone, not just the majority.
Without a length restriction, a significant minority will pick short passwords. If there are 12 people that can access my credit card information, I'm not satisfied if the majority of them picks a long password. I rather want it enforced that all of them have a long password; I think that outweights the 17 seconds an attacker gains.
In reply to Re^8: Password strength calculation
by JavaFan
in thread Password strength calculation
by cavac
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |