## # Introduction
<p><img src="https://i.imgur.com/kjWF1So.jpg" alt="Different characters on a computer screen"></p>
<p>According to a 2019 <a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/PasswordCheckup-HarrisPoll-InfographicFINAL.pdf">Google / Harris Poll</a>, 24% of Americans have used common passwords, like <code>abc123</code>, <code>Password</code>, and <code>Admin</code>. Even more concerning, 59% of Americans have incorporated personal information, such as their name or birthday, into their password. This makes it unsurprising that 4 in 10 Americans have had their personal information compromised online. Passwords with commonly used phrases and personal information makes cracking a password drastically easier.</p>
<p>You may have noticed over the years that password requirements have increased in complexity, including recommendations to change your passwords every couple of months. Compiled from industry recommendations, below is a list of passwords requirements you will be asked to test: </p>
<p><strong>Password Requirments:</strong></p>
<ol>
<li>Must be at least 10 characters in length</li>
<li>Must contain at least:<ul>
<li>one lower case letter </li>
<li>one upper case letter </li>
<li>one numeric character </li>
<li>one special character from this list: ~!@#/$%^&#x26;*()-+={}[]|;:&#x3C;&#x3E;,./?</li></ul></li>
<li>Must not contain the phrase <code>password</code> (case insensitive)</li>
<li>Must not contain the user's first or last name, e.g., if the user's name is <code>John Smith</code>, then <code>SmItH876!</code> is not a valid password.</li>
</ol>
<p>Here is the dataset that you will investigate this project:</p>
<div style="background-color: #ebf4f7; color: #595959; text-align:left; vertical-align: middle; padding: 15px 25px 15px 25px; line-height: 1.6;">
    <div style="font-size:20px"><b>datasets/logins.csv</b></div>
Each row represents a login credential. There are no missing values and you can consider the dataset "clean".
<ul>
    <li><b>id:</b> the user's unique ID.</li>
    <li><b>username:</b> the username with the format {firstname}.{lastname}.</li>
    <li><b>password:</b> the password that may or may not meet the requirements. <i>Note, passwords should never be saved in plaintext, always encrypt them when working with real live passwords!</i></li>
</ul>
</div>
<p>Warning: This dataset contains some <strong>real</strong> passwords leaked from <strong>real</strong> websites. These passwords have been filtered, but may still include words that are explicit and offensive.</p>
<p>From here on out, it will be your task to explore and manipulate the existing data until you can answer the two questions described in the instructions panel. Feel free to import as many packages as you need to complete your task, and add cells as necessary. Finally, remember that you are only tested on your answer, not on the methods you use to arrive at the answer!</p>
<p><strong>Note:</strong> To complete this project, you need to know how to manipulate strings in pandas DataFrames and be familiar with regular expressions. Before starting this project we recommend that you have completed the following courses: <a href="https://learn.datacamp.com/courses/data-cleaning-in-python">Data Cleaning in Python</a> and <a href="https://learn.datacamp.com/courses/regular-expressions-in-python">Regular Expressions in Python</a>.</p>

## Requirement 1:
Must be at least 10 characters in length

In [1]:
import pandas as pd

logins= pd.read_csv("datasets/logins.csv")

print(logins.tail())

      id         username                  password
977  978    autumn.alford                  pink3602
978  979    miriam.haynes  Gizzard.Muse+Patters_857
979  980     genaro.russo             Rm3OwUfobjYxq
980  981       lora.quinn                   bn#_k:}
981  982  elmer.mccormick              IzXEo2ghZBJm


In [2]:
length_check = logins['password'].str.len() >= 10

valid_pws = logins[length_check]
bad_pws = logins[~length_check]

print(valid_pws.tail())

      id         username                  password
975  976     freeman.rose              cHw2Leth5JXY
976  977    monica.flores               *;~a8dq5%s'
978  979    miriam.haynes  Gizzard.Muse+Patters_857
979  980     genaro.russo             Rm3OwUfobjYxq
981  982  elmer.mccormick              IzXEo2ghZBJm


## Requirement 2:
Must contain at least:
    * one lower case letter
    * one upper case letter
    * one numeric character
    * one special character from this list: ~!@#/$%^&*()-+={}[]|;:<>,./?

In [3]:
# Creating a boolean index for each character requirement
lcase = valid_pws['password'].str.contains('[a-z]')
ucase = valid_pws['password'].str.contains('[A-Z]')
numeric = valid_pws['password'].str.contains('[0-9]')
special = valid_pws['password'].str.contains('[~!@#/$%^&*()-+={}[]|;:<>,./?]')

In [4]:
char_check = lcase & ucase & numeric & special

bad_pws = bad_pws._append(valid_pws[~char_check], ignore_index=True)

valid_pws = valid_pws[char_check]

In [5]:
valid_pws.tail()

Unnamed: 0,id,username,password
966,967,taylor.kent,">L0/d""8=omzy"
970,971,noel.montoya,Riskier:Spikes_Grasped=27
971,972,josef.hoffman,Unhidden-Flatus*753-Figurer
972,973,jorge.patrick,Freedom_85!
978,979,miriam.haynes,Gizzard.Muse+Patters_857


## Requirement 3:
Must not contain the phrase password (case insensitive)

In [6]:
banned_phrases = valid_pws['password'].str.contains('password', case=False)
bad_pws = bad_pws._append(valid_pws[banned_phrases], ignore_index=True)
valid_pws = valid_pws[~banned_phrases]

In [7]:
valid_pws.tail()

Unnamed: 0,id,username,password
966,967,taylor.kent,">L0/d""8=omzy"
970,971,noel.montoya,Riskier:Spikes_Grasped=27
971,972,josef.hoffman,Unhidden-Flatus*753-Figurer
972,973,jorge.patrick,Freedom_85!
978,979,miriam.haynes,Gizzard.Muse+Patters_857


## Requirement 4:
Must not contain the user's first or last name, e.g., if the user's name is John Smith, then SmItH876! is not a valid password.

In [8]:
# Using regex '(^\w+)' to match 1 or more word characters (same as [a-zA-Z0-9_]+ ).
valid_pws['first_name'] = valid_pws['username'].str.extract('(^\w+)', expand=False)

valid_pws['last_name'] = valid_pws['username'].str.extract('(\w+$)', expand=False)

In [9]:
for i, row in valid_pws.iterrows():
    if row.first_name in row.password.lower() or row.last_name in row.password.lower():
        valid_pws = valid_pws.drop(index=i)
        bad_pws = bad_pws._append(row, ignore_index=True)

In [10]:
bad_pass = round(bad_pws.shape[0] / logins.shape[0], 2)
print("Percentage of users with invalid passwords:", bad_pass)

email_list = bad_pws['username'].sort_values()
print("Usernames with invalid passwords: \n", email_list)

Percentage of users with invalid passwords: 0.78
Usernames with invalid passwords: 
 405         abdul.rowland
309          addie.cherry
372          adele.moreno
526          adeline.bush
279           adolfo.kane
              ...        
232          yvonne.munoz
571    zachariah.jacobson
264          zachary.huff
172          zelma.abbott
49          zelma.rosario
Name: username, Length: 763, dtype: object
