6 ms·
Hi, I made this. It seems like most of you are as enraged as I am about some of these password rules. They just flat out make me mad. It's not much, but I've
by duffn 7y ago
Hi, I made this.
It seems like most of you are as enraged as I am about some of these password rules. They just flat out make me mad.
It's not much, but I've actually had one company reach out to me after making it on the list and they made their password rules less dumb.
So, if you find any particularly egregious offenders, do your part and submit a PR. It may actually make a difference.
- rolltiide 7y agoHi, this needs a checklist or ability to see severity of infractions because some of these edge cases are very dumb to elevate alongside the truly broken flows
- bscphil 7y agoYeah, compare the very first two on there right now. The first is "can't use '%'". The next one has 7 very specific rules.
- screenbeard 7y agoThat one smacks of character encoding issues or badly sanitised inputs.
- duffn 7y agoThis is a good idea. I’ll think about how to handle it.
- medmunds 7y ago> I've actually had one company reach out to me after making it on the list and they made their password rules less dumb. That’s a huge win! My pet peeve is sites that block pasting, say, from a password manager (glaring at you, Costco signup page). Those sites don’t usually include “do not paste” in the listed requirements, so this doesn’t really work with your screenshot approach. Ideas?
- pwg 7y ago> My pet peeve is sites that block pasting Firefox: about:config: dom.event.clipboardevents.enabled, toggle to "false" (default is true). Result: websites can no longer block you from pasting things into form fields on your own browser on your own computer.
- bryanrasmussen 7y agoso you can paste with the menu? Because I guess they would just catch the keyboard events?
- jtbayly 7y agoNope. Don’t think so.
- boring_twenties 7y agoI think they must block catching Ctrl+C/V/X, because those key combos work for me with that flag.
- Sylamore 7y agoI used to set this permanently, but discovered if you use facebook making status updates and comments become broken due to how fb seems to scan your input to apply styling. But I often have to toggle it off temporarily to bypass the stupid copy/paste blocks.
- Ayesh 7y agoYou can create a bookmarklet to disable paste event listeners.
- coremoff 7y agonote for firefox users, that this will break copy/paste in google docs
- CaptainMarvel 7y ago
- ehsankia 7y agoThat's awesome. This is a great idea, if there's any way to get sites to fix their stupid rules, it's by shaming them :)
- zwayhowder 7y agoI wish ING in Australia was as secure as your example site. Here we get a javascript number pad and a 4 digit numeric password. Hello 1998
- notkaiho 7y agoI am actually appalled and baffled at American Express not applying case sensitivity. Like, what the actual.
- iamnotacrook 7y agoI literally couldn't apply for an American Express card about 15 years ago because my (ISP) email address was too long. I wonder why they chose to restrict it rather than go with the standard email max length; they had to put effort in to pointlessly restrict new signups. Odd.
- myself248 7y agoBack in '99 or so, there was a company called Halibut Stuff selling T-shirts at Defcon (and presumably other events) that included a free email redirect service with purchase of a shirt. So I got a shirt that said "myself@iwenttodefcon7.andalligotwas.thislousyemailaddress.com" Not too much later, I ended up working in software validation, and I broke so many login forms with that perfectly-valid address, I lost count. Since then, Halibut Stuff dissolved and the forwarding service is long gone. If some HN reader wanted to set up a Mailinator-like service that generates absurd-yet-RFC-compliant email addresses for such testing, I think there might be a market.
- boring_twenties 7y agoLike anyone would actually use such a testing service. Until a few years ago it was fairly commonplace for sites to reject my perfectly valid addresses just because they had more than one period (i.e., a subdomain) or in one case, ended in the .us TLD.
- OGWhales 7y agoLikely because of integration with legacy tech.
- dhmiller 7y agoI remember when their max password length was 8 characters. It blew my mind that a (effectively) bank had such terrible requirements. At least they fixed that
- mkagenius 7y agoAmazon mails to change your password every three months. How does one come up new passwords every three months?
- sbarre 7y agoUsing a password manager. Most include functionality to re-generate/rotate a record's password in-place, and then copy the new one to the clipboard (or even directly into the web page). I use 1Password and even though I agree that forced password rotation is dumb, this makes it painless.
- slaymaker1907 7y agoYou should have an honor roll for companies which were bad but fixed their dumb password rules.