4 ms·
I've run into the same thing a bunch! I wish I could remember the companies to "name and shame". Some of the variations on password complexity I've seen have be
by registeredcorn 4y ago
I've run into the same thing a bunch! I wish I could remember the companies to "name and shame". Some of the variations on password complexity I've seen have been:
1. Allows any input length for password, but has a limit of X characters. Annoying because it makes it a guessing game, like you were talking about.
2. Stops accepting input for password after it hits X character limit. Annoying because you can go for months thinking you're using a 30 character password, and come to find out it's actually 8. Hard to catch if you aren't paying attention to how long your obscured password is.
3. 1 or 2, but they have a rule against all special characters. I think this is supposed to be some weird attempt at preventing SQL injection?
4. 1 or 2, but they have a rule against all special characters and numbers. I've only seen this once, but I remember dropping the service after I realized what the problem was. It was years ago, during the era when something like "banana" or "pencil" was considered a strong password.
5. 1 or 2, but they have a rule against some special characters. Usually ! @ and #, or ! # % will be permitted, but other special characters will not be permitted. I suspect this is because customers "keyboard walk" with shift+123. I.e. asdf123ASDF!@# or QWER!#%qwer135 Basically, the company allows for more predictable passwords in order to prevent extra tickets being filed.
Generally, when I run into login problems, I drop my password down to 12, since that's a pretty common length; I believe it meets a minimum length for a DOD standard? If that doesn't work, I drop it down to 8. If it's still not working, then I start removing special characters and capitalization.
It's really gross that I can't expect to use a 30 - 60 character password in a predictable manner across the entire internet. In a way, I almost prefer things to be the way they are though, so I can have a better idea of which companies are strong on security, and which are either uninformed, or justify misconfigurations as "improving customer satisfaction" over minimum security policies.