Context is that I had to register for a lot of accounts recently and some of the rules really make no sense.

Not name-and-shaming, but the best one I’ve seen recently is I might have accidentally performed an XSS attack on a career portal using a 40-digit randomly generated password…

  • @ObsidianNebula@sh.itjust.works
    link
    fedilink
    0
    edit-2
    1 year ago

    I had to log back into an account for an app (I think Taco Bell) that decided to remove passwords entirely without any notice. You typed in your email address, had to open your email account and click a link they sent you, it would open a webpage, which would then have a button to open the app again. If I remember correctly too, it would only work on Chrome, so I had to copy and paste the link since Chrome isn’t my default browser that automatically opens from my mobile email.

    Besides that, I remember some website required a special character from an extremely small list and wouldn’t allow two of the same letter back-to-back.

  • @weker01@sh.itjust.works
    link
    fedilink
    01 year ago

    Extremely limited password length. I think it was around 6 or 8 characters. Exactly! So every password was the same length.

    No other requirements. The best part? It was a bank. But not a customer facing service.

    • @Treczoks@lemmy.world
      link
      fedilink
      01 year ago

      Banks are amazingly bad at digital security. I once was in a bank (where my wife had an account) where they used first generation wireless keyboards. The ones that did not encrypt anything and could be received to a distance of up to 10m, more if you had a better antenna. I told them about the security issues, but they did not understand. I went to the newspaper agent and bought the newest edition of a computer magazine that had detailed descriptions of how to eavesdrop on those keyboards, returned to the bank, and handed them the article. Which featured exactly their keyboard model as the title photo. I told them “If you don’t understand this, it’s fine, but then give it to the person responsible for your IT and security, they should know how to deal with this.”

      Next time we were there, they still had the insecure keyboards. Yes, the IT department had told them that they should replace them with wired ones, but they rejected it, because the wireless ones were sooo convenient. Our next move was to close my wifes’ account there.

  • @ryathal@sh.itjust.works
    link
    fedilink
    01 year ago

    Passwords that must contain a special character, but only from a list of three special characters.

    Passwords that must be changed every 3 months.

    Absurdly narrow length requirements, im 80% sure I saw one that required 8-16 characters.

    All dictionary words were banned from being in a password regardless of length, so passphrases weren’t allowed.

    • @NJSpradlin@lemmy.world
      link
      fedilink
      0
      edit-2
      1 year ago

      I redid one of mine yesterday; 3-months, exactly 8 characters, must use a symbol from the three approved ones (#$@).

      I hate it, I wish they’d abandon that system or change the encryption requirement to match our other systems that use our physical badges.

      Edit: it’s really dumb around the holidays, too. We’re off for Thanksgiving, Christmas and New Years so I really only got a few weeks out of that last one.

    • @Susaga@sh.itjust.works
      link
      fedilink
      English
      01 year ago

      It’s always quote unquote fun finding out what words are and are not in their dictionary. I got by using a bunch of nerd words, but apparently Aragorn is not allowed.

    • qantravon
      link
      fedilink
      English
      01 year ago

      I’ve definitely had one that was 8-12 characters before…

  • 🇰 🌀 🇱 🇦 🇳 🇦 🇰 🇮 🏆
    link
    fedilink
    English
    0
    edit-2
    1 year ago

    The most basic rules commonly required everywhere. When you have such specific rules, it ironically actually makes finding the password through brute force easier because you can eliminate a bunch of variables that could have existed without all the rules. I can eliminate any permutation under 8 characters, doesn’t contain a number, and doesn’t contain a special character.

    It will still possibly take a billion years to guess, but it could have been two billion without the rules.

    Of course, I also find it wild that the metric for how good an encryption or password system is, is just how long it would take to guess every possible combination of input it could be, sequentially. It doesn’t account for a brute force attempt that just selects random inputs. It could take until the heat death of the universe… It could take 3 seconds. It’s up to chance at that point. Not to mention all the easier ways of getting a password. Like gaslighting the person who knows it into giving it up.

    • @frezik@midwest.social
      link
      fedilink
      01 year ago

      It’s something like the second law of Thermodynamics. It’s probability, not absolute. It’s possible all the gas molecules in the room arrange themselves one corner, but it’s fantastically unlikely. It’s possible to choose the right encryption key to a 256-bit cipher at random the first time, but it’s fantastically unlikely.

  • lemmyng
    link
    fedilink
    English
    01 year ago

    “Password must contain letters numbers, and at least one of these special characters.”

    Turns out, half of those special characters weren’t allowed 🫠

  • @TootSweet@lemmy.world
    link
    fedilink
    English
    0
    edit-2
    1 year ago

    12 characters, upper/lower/special requirement, and no more than two occurrences of the same character together. That’s FedEx.

    Two other thoughts on the topic:

    • Websites/apps/etc should always list their password requirements on the login page to make it easier to determine what password you used for the site in question.
    • There are plenty of websites where I literally log in only by using the “forgot password” flow because their password requirements are so ridiculous.
  • Like the wind...
    link
    fedilink
    English
    01 year ago

    Anyone remember the Password Game?

    I personally hate character limits. I understand minimum character count, but I can’t have more than 15 characters? Bruh

  • The most funny one was a professional and rather costly password checking tool.

    Besides the usual other rules, it had a rule that the new pw must not be similar to the old one. For similarity, this thing checked each character in it’s place.

    So you could have the old one:
    “MyAssMy$1” and the new one:
    “$1MyAssMy” and it was not similar at all :)

  • Boomkop3
    link
    fedilink
    01 year ago

    It happens a bit too often that I make an account somewhere with a long, generated password and then when I log in it throws errors at me.

    But a few times a website didn’t just show me an error, I got the whole crash dump including their encryption approach and versioning

  • @otp@sh.itjust.works
    link
    fedilink
    01 year ago

    Anything that requires regular password resets. It’s fine if it’s changed on the site and in the user’s vault automatically, but if a user has to type in their password with any sort of regularity, it’s a recipe for disaster to require regular changes.

    People write predictable or formulaic passwords, or just end up resetting their password more often than necessary because they forgot it (making them more susceptible to phishing).

    • @Susaga@sh.itjust.works
      link
      fedilink
      English
      01 year ago

      There was an episode of Elementary where they were able to find the victims password on a post-it note, because the company requires a new password every month and he didn’t want to remember a new one that often.

    • Cousin Mose
      link
      fedilink
      01 year ago

      I memorized a handful of randomly generated passwords in high school (around 2005) and never looked back.

      These days I use a password manager, but for semi-low security stuff (on my LAN) I use one, for my Apple account a long combination of three. And that’s it! The password manager is where it’s at.

      Just one of my passwords was leaked in data breach (from back when I was younger and recycled passwords) so that one’s out, but otherwise I’m doing pretty well with the memorized randomly generated passwords.

  • @Dagwood222@lemm.ee
    link
    fedilink
    01 year ago

    [offtopic?]

    Debbie’s password is “PlutoGoofyMickeyMinnieDaffyBugsThorLosAngles”

    She was told that the password needed seven characters and a capital.

  • @CarbonatedPastaSauce@lemmy.world
    link
    fedilink
    English
    01 year ago

    A company I used to work for is big enough that everyone reading this has heard of it. They had this wonderful security nightmare going on:

    When you were hired, the company would issue your user credential with a standard password that was “CompanyName1” and require you to immediately change it at first logon. Everyone knew this password because everyone got it when they were hired.

    Password policy required everyone to reset their password every 60 days. Not the worst ever but still pretty aggressive. And with the rise of all the mobile devices connecting with your corp account it was getting to be a worse and worse experience.

    Can you guess yet how these two policies are linked in my story?

    Well, some of the C-Suite executives didn’t have time for any of these security shenanigans. So they would have their executive support person log into an administrative console and reset the exec’s password every 59 days to the same value that it currently had, thereby bypassing the password re-use filter.

    That value they were continuously setting was… “CompanyName1”

    I know of at least two executives that were doing this while I worked there.

    • Cousin Mose
      link
      fedilink
      01 year ago

      When I was in middle and high school the school district would always do this at the beginning of the school year.

      One year my best friend moved away so in the following years I discovered his account still existed. If I was in the mood to hack (dumb stuff like forging email with their horrible SMTP server for example) I’d just find another computer I wasn’t just using and log in using the default password.

  • Boomkop3
    link
    fedilink
    01 year ago

    Facebook got caught having a flat text file being send around between employees to make accessing data easier. That text file contained tens of thousands of peoples username and password.

    Why? Facebook being facebook I guess

  • @Railing5132@lemmy.world
    link
    fedilink
    01 year ago

    I’ve encountered a few sites that restricted repeating or sequential characters. Of course told after failing the first creation attempt. Makes things like randomly generated passphrases fun to figure out. Particularly when their idea of “sequential” involves both in alpha/numerical order, but also adjacent spacing on the (assumed?) qwerty keyboard!

  • qantravon
    link
    fedilink
    English
    01 year ago

    Most absurd was from a job I had in college. This was the password to log into an ancient dumb terminal (literally a monochrome black and green display) on a local-only network that only handled our time clock.

    Requirements:

    • 8 characters exactly
    • You supply the first 4, the system generated the last 4
    • I can’t remember if it allowed numbers, but there were definitely no special characters and I think it was also case-insensitive

    Required to change password every 30 days.