Dumb Password Rules
21–30 of 86 posts
Re: Dumb Password Rules
#22My favorites are the ones where you can't use more than a certain number of characters or where you can't use special characters.
Sabre Red is great: 7 or 8 characters, no Q, no Z.
Re: Dumb Password Rules
#23My favorites are the ones where you can't use more than a certain number of characters or where you can't use special characters.
Re: Dumb Password Rules
#24One ongoing annoyance is that it's increasingly difficult to generate a random string will be meet a given site's Dumb Password Rules, because so many sites have them, and there's surprisingly little overlap in the rules.
I would really like to see a database of sites and their corresponding Dumb Password Rules, so that I can tell KeePass (or any other app using the database) to generate me a new Mindware password, or a new Williams-Sonoma password, and get a random string that conforms to all the relevant DPRs.
Re: Dumb Password Rules
#25My favorites are the ones where you can't use more than a certain number of characters or where you can't use special characters.
Re: Dumb Password Rules
#26In the same spirit, can we please do away with the idea of expiring passwords -- and then enforcing that we can't even re-use our last X number of passwords. It just causes locked out accounts, written down passwords or adding on one more of whatever character was at the end.
There is a specific reason for having "cant reuse last X number of passwords" combined with having an "expiring password" rule. The idea is that if someone was silently in your account, and doing a "stealth" attack - then they could change your password, then change it back to your original password, thus "resetting" your expiring password timer, giving them more time in the system - and you would not know that the p…
Re: Dumb Password Rules
#27In the end, what is more important: seeing the situation improved or just complaining?
Re: Dumb Password Rules
#28My favorites are the ones where you can't use more than a certain number of characters or where you can't use special characters.
Like Microsoft account passwords (at least for office 365). I don't understand why they do this.
Re: Dumb Password Rules
#29How about allowing special characters and not just a-zA-Z0-9.
Usually, there is some legacy system behind the scenes that can't be updated because reasons. Not an excuse, but it isn't always that easy.
Re: Dumb Password Rules
#30I use KeePass to store all of my (randomly generated) passwords. One ongoing annoyance is that it's increasingly difficult to generate a random string will be meet a given site's Dumb Password Rules, because so many sites have them, and there's surprisingly little overlap in the rules. I would really like to see a database of sites and their corresponding Dumb Password Rules, so that I can tell KeePass (or any other…