Rule n° 202 - Passwords can be chosen and changed by the user

For many users, the default chosen passwords are too complex to remember. Being able to choose or change their password provides real added value for the users.

#Accessibility #Development #Security

Goal

  • Allow users to choose personalized passwords.
  • Avoid users struggling to remember their passwords every time they log in.

Solution technique

Provide an online procedure allowing the choice of a personalised password as soon as the account is created or by subsequent modification of the automatically generated passwords.

Provide access to password modification from user account management or failing that using the identification form.

Moyen de contrôle

On any website offering password access:

  • Check that it is possible to enter the password of your choice when creating the account or, in the case where the password is automatically generated by the online service, check that it is possible to modify it after registration.