Web Developer Security Checklist
Michael O'Brien

Just one minor touch of a niggle…

[ ] Implement simple but adequate password rules that encourage users to have long, random passwords.

Passwords don’t need to be all random characters, if you have to remember them (like your password manager password), even 4 random words, if the total characters is more than 12 is significantly better than 8 random characters…. As to random characters, allow any character, and don’t require certain characters, just require a minimum length and/or complexity.

