4 ms·
This requirement is in section 8.3.9 of the PCI DSS[0], and only applies to single-factor authentication implementations, two-factor auth removes this requireme
by clwg 1y ago
This requirement is in section 8.3.9 of the PCI DSS[0], and only applies to single-factor authentication implementations, two-factor auth removes this requirement.
[0] https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard...
- throwaway72046 1y agoYour broker/bank still needs to do it, unfortunately... someone please fix this :( [0] https://www.finra.org/filing-reporting/entitlement/password-requirements https://www.finra.org/filing-reporting/entitlement/password-...
- dmoy 1y agoWhat's the scope of that? Not consumer accounts I imagine? I haven't had to change my bank account passwords in over a decade.
- Mtinie 1y ago> If the password length is 12 to 15 characters, it will be valid for 180 days > If the password length is 16 to 32 characters, it will be valid for 365 days Madness.
- lofties 1y agoI'm a big fan of "should not include profanity, words of a vulgar nature". It's not unthinkable my password manager comes up with a chain of letters that at one point will include "fuck".
- tiltowait 1y agoThis comment reminded me of a talk I saw[1] about Apple's password generation algorithm. Apparently (and unsurprisingly), they have a list of offensive terms the system is designed to avoid. I expect this is common-enough practice in most popular password managers, but probably not all. [1] https://www.youtube.com/watch?v=-0dwX2kf6Oc https://www.youtube.com/watch?v=-0dwX2kf6Oc
- notpushkin 1y agoIt would be fun to make a passphrase generator that always includes a profanity.
- HPsquared 1y agoSo long as they factor that into the "bits of entropy" calculation.
- yencabulator 1y agoDibs for calling it misenthropy. Entropy mixed with misantrophy.
- zavec 1y agoNow I'm trying to remember where I read the story about somebody who was in a programming class and was writing some program that took user input, and figured that it should be smart enough not to repeat curse words. So they started writing down all the curse words it should know not to say, and that was about the extent of what they had done when the teacher came around to see how everything was going.
- WarOnPrivacy 1y ago> I'm a big fan of "should not include profanity, words of a vulgar nature". On my first Wireguard testbed, WG's keygen dropped one at the front of the key. It remains my most treasured digital possession.
- seadan83 1y agoIt kinda is good personal policy IMO for passwords you have to type to be positive affirmations. I used 'Fuckthis1!' for a moment; funny enough it was not the most moralizing thing to type all the time! OTOH, 'H@ppyH@ppyJoyJoy!!' was always a small mood lift.
- andrewaylett 1y agoWord list based passphrases mostly avoid this, by not including those words. Which still doesn't mean you won't get something offensive, of course, it'll just be a string of four words instead of four letters.