Option to reduce minimum length of Generator output (passwords and passphrases)

The minimum length of password generated from the password generator is 5 characters. But I frequently use the password generator to generate PINs, which are typically of 4 digits, by just selecting numbers in the options. It would be helpful if the password generator can allow generating passwords of less than 5 characters [numbers in my case].

Same case with the passphrase generator. The minimum words it can generate is 3. While I use the passphrase generator to generate a word to add as a salt to my self created password. It would be helpful if the passphrase generator can allow generating passphrases of 1 words to use as addition to my password.

I know we can just select part of the generated output to use as needed but then my mind gets confused as to which 4 numbers to select or which word to select. And it should be a very simple task to allow selecting smaller number.

I know reducing the minimum number of characters or words carries the risk that some users will create even shorter passwords. But this seems to punish other users to keep not so knowledgeable users safe [probably].

1 Like

I agree with your request. I did modify the title to be more clear (old title was: “Minimum length of password generator output”; new title: “Option to reduce minimum length of password generator output”) .

@Stronuk If you would be for a minimum of 4 characters for “passwords”, then there is an existing feature request for that: Allow for 4 character numeric "passwords" for PIN creation

Otherwise, what would be your minimum length for passwords (and passphrases)?

(actually, I think I would be for “1” for both…)

Thanks for linking that post. My search did not bring up any posts regarding minimum password length from password generator. I would suggest the new limit be kept 1 for both password and passphrase. No point in limiting the use of the software artificially.

Also, the point that it will reduce security is not Bitwarden’s lookout. It is up to the website / application requesting the user to create a password to enforce password complexity requirements.

Enabling this option I can use a random number or symbol as the separator between the words in a passphrase. But for this I need to be able to generate single character random numbers / symbols from the password tab.

Expanding on this, the password generator can have custom field syntax based password generator. So users can define their own custom fields in the password generator and it will allow us to mix and match elements to create custom passwords in desired formats. eg. <1word><2numbers><2symbols> or <8alphabets><2numbers>

To reflect, that passphrases are also meant, I changed your title slightly. (yours was “Option to reduce minimum length of password generator output”)

Hello,

there is a policy to set the lowest settings for generating passwords. That’s a nice setting.
But there are services on the web that have (sadly) stupid settings for the passwords like a max length or something like that. It would be cool if users can change the settings for the generator in order to generate valuable passwords.

Thank you in advance

Hey @matcha, thanks for the feedback, for the odd credential that is weaker than the policy being enforced, you can always use the website version here. A manual entry can be inserted into the password field.

@matcha I moved your post into this feature request to the same topic now.

some websites have password limits, the minimum limit that Bitwarden generates will be over the limit. so, please reduce the passphrase words minimum limit to 2

2 Likes

@b49478 Welcome to the forum!

What types of websites were you planning to use such a password for? Can you provide some examples (real or hypothetical)? With a 2-word passphrase, there are only 60 million possibilities, which makes the password very easy to guess. Is there a reason why you can’t use a password consisting of a random string of characters instead?

4 Likes

there are a lot of traditional website that don’t support long password. as my country, china, Baidu support only 15 chars long password.

as for the security, the different divider “-”, caps or not, different position of the number, could add up to a lot of possibilities.

for the a random string of characters, it is not easy to type on a different device.

1 Like

Is it really that difficult to type only five characters? (for example, N2y&8)

Yes please. I just tried to generate a new password for my Spectrum account. They have a maximum character limit of 20. Everything I generated with BW was over that because of the 3 word minimum. There should either be an option to use ‘2’ words (have it default to 3 each time) or to let me specify the character maximum.

A two-word passphrase is about as secure as a password consisting of 5.5 random lowercase letters.

When faced with a low character limit, you would be better off switching over to the password generator, instead of the passphrase generator.

Fortunately for us Bitwarden users, it generally is not necessary for most of our passwords to be memorable or easy to type, due to the magic of auto-fill.

2 Likes

That’s why I also suggested the alternative of being able to specify a character limit. At 20 characters, that could be 3 words if it picked some long and some short words.

And normally I use passwords, but sometimes I need to manually type in a password on a different computer or device and typing words is much easier than random gibberish. :slight_smile:

1 Like

The character limit is 20 . I think it should be more than 20.

@b49478 @kelemvor @mranil I merged your posts with this feature request to the same topic.