Weak password policy

Weak password policy in C#

Description

Allowing very short or common passwords in ASP.NET Core Identity can let users choose passwords that are easy to guess or vulnerable to brute-force attacks.

Potential impact

  • Increased risk of password guessing, credential stuffing, and privilege escalation.

Remediation

Set a minimum length appropriate to the authentication method and block common or compromised passwords. Do not judge strength solely by requiring a mixture of character types. NIST SP 800-63B-4 requires at least 15 characters for single-factor authentication and permits a minimum of eight for passwords used only as part of MFA.

Examples

Before

csharp
options.Password.RequiredLength = 6;

After

csharp
options.Password.RequiredLength = 12;

Explanation:

  • Before: Weak password requirements can make passwords easier to guess or crack.
  • After: The example raises the minimum length to 12, but this alone does not satisfy a complete authentication policy. Use a longer minimum for single-factor authentication, and also consider MFA and compromised-password blocking.

References