I recently got an upgrade for a framework I use and saw this in the changes documentation:

And I sighed. This is truly bad advice, bad code and we know better!

Long passwords are better than requiring mixed case and/or special characters.

I have written about this many times, for instance here, here, here, here and here.

Of course, there is another solution: Let’s solve the problem that we are trying to solve with logins and passwords differently.

