Homestyx hydra

R1:1f6a4cfffe58

Prevent users from selecting excessively bad passwords based on their username or email address

Summary:
Ref T13216. We occasionally receive HackerOne reports concerned that you can select your username as a password. I suspect very few users actually do this and that this is mostly a compliance/checklist sort of issue, not a real security issue.

On this install, we have about 41,000 user accounts. Of these, 100 have their username as a password (account or VCS). A substantial subset of these are either…
Repository: R1 hydra
Commit Date: Nov 6 2018