3 ms·
Look at their password requirements : 1 symbol, 1 uppercase letter, 1 lowercase letter, 1 number - when we know that security folks at this point would say "any
by robust-cactus 4y ago
Look at their password requirements : 1 symbol, 1 uppercase letter, 1 lowercase letter, 1 number - when we know that security folks at this point would say "any easy to remember phrase is better than random characters". And they will fine you to death if you don't enforce all the characters.
There's a few mentions online about companies that have gone out of business or fined like crazy - whether they're warranted or not isn't the question. There's an article on tech crunch about Fidzup that shares a nice extreme case. I don't think 1 nations DPA should be able to unilaterally make decisions for entire platforms or the planet. Moreover, they're absolutely terrible to work with.
- Rexxar 4y agoI see what you say in old recommendation but a recommendation is just a baseline you can change if you justify it. The new version seems to be in line with what you want : https://www.cnil.fr/sites/default/files/atoms/files/draft_recommendation_-_passwords_and_other_unshared_secrets_version_for_public_consultation.pdf https://www.cnil.fr/sites/default/files/atoms/files/draft_re... For Fidzup there was no monetary sanction. Investor have just walk away when they learned there was an inquiry. All sanction are published : https://www.cnil.fr/fr/thematique/cnil/sanctions https://www.cnil.fr/fr/thematique/cnil/sanctions I don't find anything crazy.