Strengthen the use of the Master Password.

- Use 30k iterations instead of 1.
- Enforce minimum password length of 8 characters.
- Adjust strength meter accordingly.

This resolves #82.
This commit is contained in:
wolfbeast 2018-04-18 14:05:21 +02:00 committed by Roy Tam
commit 522a346ef8
4 changed files with 16 additions and 9 deletions

View file

@ -167,8 +167,8 @@ function setPasswordStrength()
// length of the password
var pwlength=(pw.length);
if (pwlength>5)
pwlength=5;
if (pwlength>10)
pwlength=10;
// use of numbers in the password
@ -190,7 +190,7 @@ function setPasswordStrength()
upper=3;
var pwstrength=((pwlength*10)-20) + (numeric*10) + (numsymbols*15) + (upper*10);
var pwstrength=((pwlength*5)-20) + (numeric*10) + (numsymbols*15) + (upper*10);
// make sure we're give a value between 0 and 100
if ( pwstrength < 0 ) {
@ -227,6 +227,12 @@ function checkPasswords()
}
}
// Never accept short passwords < 8 chars
if (pw1.length < 8) {
ok.setAttribute("disabled", "true");
return;
}
if (pw1 == pw2) {
ok.setAttribute("disabled", "false");
} else