Bad Password Policies
21–30 of 45 posts
Re: Bad Password Policies
#22Honestly, I don't get why a service would enforce a password policy at all. They should warn users about what makes a good password, and tell them when their password sucks ("your password is weak and would be crackable in 3 minutes") but if someone wants for some reason to use 123456 as a password, that's their own problem.
[0] I'd say Dropbox, but you shouldn't be putting confidential data in Dropbox.
Re: Bad Password Policies
#23I find it extremely frustrating how many services (Microsoft included!!) won't allow me to use spaces in my passwords. Why on earth do they care which characters I choose for my passwords? So much for "correct horse battery staple"...
you can try camelCasing your passwords, same effect really
On the other hand, forbidding spaces is absolutely misguided.
Re: Bad Password Policies
#24I find it extremely frustrating how many services (Microsoft included!!) won't allow me to use spaces in my passwords. Why on earth do they care which characters I choose for my passwords? So much for "correct horse battery staple"...
you can try camelCasing your passwords, same effect really
Re: Bad Password Policies
#25I find it extremely frustrating how many services (Microsoft included!!) won't allow me to use spaces in my passwords. Why on earth do they care which characters I choose for my passwords? So much for "correct horse battery staple"...
FastMail provides a lot of different services over many
different protocols. To ensure that your password is
compatible with all of them, and the many (often
slightly buggy) clients out there, we only allow
the characters A-Z, a-z, 0-9 and !?@#$%^&*()-=_+[]{}.,:;/\|~"'`.
Which I understand, but how about a checkbox that says "for goodness sake, I'm a grown up, I promise not to moan if I use a "buggy" client, now please let me the password of my choosing."Re: Bad Password Policies
#26Re: Bad Password Policies
#27Earlier quoted context omitted.
you can try camelCasing your passwords, same effect really
Unless the website silently lowercases all passwords. A lot of them do, in the name of making life easier for people who have Caps Lock on.
Re: Bad Password Policies
#28Re: Bad Password Policies
#29One of the most ridiculous password policies I ran into recently limited passwords to a maximum length of 8 characters. I was absolutely stunned. And for whatever reason, they also enforce that it must contain both a capital and lowercase letter and a number, plus a minimum length of six characters.
Re: Bad Password Policies
#30The only reason i can think of why one should do this is plausible deniability for the provider. No, we weren't hacked, your password just sucks.