Forum Discussion
hooleylist
Oct 21, 2010Cirrostratus
If the characters legitimately need to be used in the app, I wouldn't hesitate to relax the policy. Password fields are generally one parameter where you allow all standard ascii metacharacters assuming the application allows them. You can still use the attack sigs to provide protection.
Aaron