Readit News logoReadit News
duffn commented on A compilation of websites with dumb password rules   dumbpasswordrules.com/... · Posted by u/duffn
gorbachev · 3 years ago
Good idea. Hope the companies listed take notes.

One of the dumbest I've seen is when the username has password-like requirements, like insisting capital letters and numbers.

duffn · 3 years ago
I've previously had somebody from Microsoft reach out to me directly about their entries and had somebody from RedHat create an issue, but I don't think either actually took action.

I'll continue to try though and am evaluate ways that the site can actually help companies update their rules.

duffn commented on A compilation of websites with dumb password rules   dumbpasswordrules.com/... · Posted by u/duffn
gorjusborg · 3 years ago
I absolutely love the concept behind the site.

I'd like to submit all the sites that disable copy/paste on their password entry, especially if they have stringent password content policy.

My randomly generated 10 word passphrase is more secure than your password policy, but I don't want to type it in by hand, you donkey.

duffn · 3 years ago
I'm glad you enjoy it! If you have any sites you like to add, please feel free to contribute. https://github.com/duffn/dumb-password-rules/blob/main/CONTR...
duffn commented on A compilation of websites with dumb password rules   dumbpasswordrules.com/... · Posted by u/duffn
thesuitonym · 3 years ago
I bounced pretty quick, because as amusing as it was, seeing a site and then a cut-off sentence about why it was there was not the best presentation.

The splash page would make more sense if it had some brief description of why sites end up there--and maybe some guidance of making decent password rules.

duffn · 3 years ago
Thanks for the feedback, the gallery seems to be not well loved, so will be re-evaluated.
duffn commented on A compilation of websites with dumb password rules   dumbpasswordrules.com/... · Posted by u/duffn
SamBam · 3 years ago
Nice, but displaying this as a gallery seems to make it harder to quickly parse all of these. The rules are all just images some hard to read at that scale, and some cut off. If you click on one, you can't page to the next, you have to go back to the gallery and click on the next.

Seems like it would be nice to have the actual set of rules next to each example, and to be able to page through the examples.

I also find having to page through the home page a little odd.

duffn · 3 years ago
Good feedback, thanks! Pagination through items would be a great addition and the gallery seems to be not loved, so will be re-evaluated.
duffn commented on A compilation of websites with dumb password rules   dumbpasswordrules.com/... · Posted by u/duffn
armchairhacker · 3 years ago
Suggestion: add a rating system, because some of these are more dumb than others. Also add an indicator or separate rating for requirements that make the passwords too easy to guess like “no more than 8 characters”. e.g.

> Coil

> Does not allow simple characters and sequences such as '4587' or 'efgh' in password & necessarily requires numeric values.

or Apple’s requirement that you cannot have more than 3 consecutive characters, seem reasonable to me. Certainly these rules ban perfectly fine passwords, but they’re a lot better than something like “must be between 8 and 16 characters and contain one uppercase, lowercase, number, and special character, but not these special characters, and it also cannot have an edit distance of 3 from your user ID”

duffn · 3 years ago
Good idea! I've added an issue for discussion here: https://github.com/duffn/dumb-password-rules/issues/445
duffn commented on A compilation of websites with dumb password rules   dumbpasswordrules.com/... · Posted by u/duffn
artemonster · 3 years ago
Should be rule-centric rather than site thumbnail centric. I came to see dumb rules, not a bunch of thumbnails
duffn · 3 years ago
Please open an issue to discuss any improvements you'd like to see!
duffn commented on Sites with dumb password rules   github.com/dumb-password-... · Posted by u/enjoyyourlife
rolltiide · 6 years ago
Hi, this needs a checklist or ability to see severity of infractions because some of these edge cases are very dumb to elevate alongside the truly broken flows
duffn · 6 years ago
This is a good idea. I’ll think about how to handle it.
duffn commented on Sites with dumb password rules   github.com/dumb-password-... · Posted by u/enjoyyourlife
duffn · 6 years ago
Hi, I made this.

It seems like most of you are as enraged as I am about some of these password rules. They just flat out make me mad.

It's not much, but I've actually had one company reach out to me after making it on the list and they made their password rules less dumb.

So, if you find any particularly egregious offenders, do your part and submit a PR. It may actually make a difference.

u/duffn

KarmaCake day135December 6, 2016View Original