2 ms·
My most memorable policy as an end user was as a consulting client for a huge bank. On top of the usual length, character type, and password changing requiremen
by fancyfish 7y ago
My most memorable policy as an end user was as a consulting client for a huge bank. On top of the usual length, character type, and password changing requirements, the password could not use substrings of 3+ characters from any of your prior passwords.
They were also required to pass a black-box “complexity” algorithm, and the vast majority of passwords generated by my password manager inexplicably failed this bar.
So every 6 weeks I would set aside about 20 minutes to generate new passwords of varying length in my password manager until one would be accepted as the new password.
- other_herbert 7y agoThe terrible implication with that is, is that somewhere the plain text of your history of passwords was stored