Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

3
  • 7
    If you have any influence on these requirements, please push back against them. Forbidding some special characters in passwords is a sign that something is broken in your infrastructure: either it can be exploited by something other than a password, or passwords are being passed around to places that can't keep them secret. Requiring special characters in passwords is widespread, but misguided advice that pushes people to choose weaker passwords. security.stackexchange.com/q/131056 security.stackexchange.com/questions/16455 security.stackexchange.com/questions/6095 Commented Dec 3, 2021 at 11:48
  • 2
    Even just the fact that you're doing password validation in bash is a red flag. It's possible, but hard to verify that the password won't leak due to a bug in another part of the script, or that it won't leak through a side channel in the password validation code, or that it won't end up in a log somewhere. Commented Dec 3, 2021 at 11:50
  • 2
    @Gilles'SO-stopbeingevil' fully agree with your suggestion, but the bug in question is in Wordpress which doesn't accept these characters in the password when passed through Wp-CLI. Commented Dec 3, 2021 at 13:58