Previous Article | Back to News Summary | Next Article
Announce News Post #2296

Updated Password Policy

Written by: Roark Libertas
Date: Sunday, February 9th, 2014
Addressed to: Everyone


We've made an update to Lusternia's password policy. Previously our
rules were between 4 and 10 characters and no spaces. These are bad
rules, as they limit the complexity of the passwords rather than
enhancing it. These rules made sense based on how we implemented
passwords in the late 1990s (when it was just Achaea and Lusternia
didn't exist). But we've long since implemented more secure passwords
storage, making these limitations obsolete.

We are now enforcing a new password policy. New passwords must:
+ Be at least 8 characters.
+ Have at characters from least two of the following categories: upper
case, lower case, digits, and everything else (symbols, punctuation,
spaces, etc.). Note that spaces are now allowed.
+ Not contain your character name. (Same as before.)

Your existing passwords are unchanged; this only applies to new
passwords. Nonetheless, if your password does not comply with these
rules then I encourage you to change it.

I'll also give some advice which holds true for any passworded internet
service (GMail, Facebook, etc.), not just Lusternia. The best posswords
are not complicated ones but rather long ones. For example, the
passwords "I love Lusternia more than Angry Birds" is harder to crack
than "Lust3rn1@". Here's a funny comic that explains it:
http://xkcd.com/936/


Penned by My hand on the 5th of Shanthin, in the year 375 CE.


Previous Article | Back to News Summary | Next Article