Skip to main content

A bad password generator for bad websites with bad password policies

Project description

LANGUAGE VERSION build status MAINTAINED LICENSE STYLE

To create and remember passwords for online services, the best practice for most folks online is to use a password management tool such as Bitwarden to generate long, cryptographically random passwords. Then, a very strong passphrase is used to lock the password manager.

Unfortunately, in a misguided attempt to encourage users to choose better passwords, many websites and apps enforce restrictive password policies. These policies inhibit users from using cryptographically random password generators: a long, high-entropy password is more likely to violate such rules, which means a security-savvy user may have to attempt several “random” passwords before one is accepted. This punishes users who are trying to follow best practices.

Enter dumbpw. dumbpw allows you to configure a set of rules, and then it will generate a cryptographically secure password that conforms to those dumb rules.

If all you need is a password generator, you should not use this.

Installation

pip3 install dumbpw

Usage

$ dumbpw --help
Usage: dumbpw [OPTIONS] LENGTH

Options:
--version                       Show the version and exit.
--min-uppercase INTEGER         The minimum number of uppercase characters.
--min-lowercase INTEGER         The minimum number of lowercase characters.
--min-digits INTEGER            The minimum number of digit characters.
--min-specials INTEGER          The minimum number of special characters.
--blocklist TEXT                Characters that may not be in the password.
                                [default: '";]
--allow-repeating / --reject-repeating
                                Allow or reject repeating characters in the
                                password.  [default: reject-repeating]
--specials TEXT                 Non-alphanumeric characters that may be in
                                the password. Pass '-' to read from standard
                                input.
--help                          Show this message and exit.

Known issues

  • dumbpw uses secrets to generate passwords. If the generated string doesn’t meet the given requirements, dumbpw discards it and generates another, until one passes. Therefore, if you ask dumbpw to generate a long password with high minimums, it will run for a very long time before terminating.

  • Likewise, if your minimums require characters that are banned in the blocklist option, dumbpw will run forever.

  • The author is neither a cryptographer, nor a security expert. There has been no formal, independent, external security review of this software. As explained in the LICENSE, the author assumes no responsibility or liability for your use of this software.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

dumbpw-1.0.2.tar.gz (6.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

dumbpw-1.0.2-py3-none-any.whl (9.0 kB view details)

Uploaded Python 3

File details

Details for the file dumbpw-1.0.2.tar.gz.

File metadata

  • Download URL: dumbpw-1.0.2.tar.gz
  • Upload date:
  • Size: 6.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.3.2 CPython/3.13.11 Linux/6.18.6-zen1-1-zen

File hashes

Hashes for dumbpw-1.0.2.tar.gz
Algorithm Hash digest
SHA256 c283fc276fe7a3405abd54675be564e8a49f6f2bcc782acd6de81a56476be479
MD5 dcded83b99316bf88bb0709264453fb1
BLAKE2b-256 6244191acd10fb7da00a3ea4d00d01aeeb0ed99f1c0d4261eb33b47b8c8b7dd7

See more details on using hashes here.

File details

Details for the file dumbpw-1.0.2-py3-none-any.whl.

File metadata

  • Download URL: dumbpw-1.0.2-py3-none-any.whl
  • Upload date:
  • Size: 9.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.3.2 CPython/3.13.11 Linux/6.18.6-zen1-1-zen

File hashes

Hashes for dumbpw-1.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 afd2051d7db07a309c16867cdaeffbf649fb502f1ab06cc6a65fc2c8ade5ba31
MD5 1206fa92ffde7c0e7baf8feee35aef84
BLAKE2b-256 fd86cc022738f526744b2673f5e258cb0340a075a82929db87fa70ffe36d6b56

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page