Description
Allowing very short or common passwords in ASP.NET Core Identity can let users choose passwords that are easy to guess or vulnerable to brute-force attacks.
Potential impact
- Increased risk of password guessing, credential stuffing, and privilege escalation.
Remediation
Set a minimum length appropriate to the authentication method and block common or compromised passwords. Do not judge strength solely by requiring a mixture of character types. NIST SP 800-63B-4 requires at least 15 characters for single-factor authentication and permits a minimum of eight for passwords used only as part of MFA.
Examples
Before
csharp
options.Password.RequiredLength = 6;
After
csharp
options.Password.RequiredLength = 12;
Explanation:
- Before: Weak password requirements can make passwords easier to guess or crack.
- After: The example raises the minimum length to 12, but this alone does not satisfy a complete authentication policy. Use a longer minimum for single-factor authentication, and also consider MFA and compromised-password blocking.