66

Context is that I had to register for a lot of accounts recently and some of the rules really make no sense.

Not name-and-shaming, but the best one I've seen recently is I might have accidentally performed an XSS attack on a career portal using a 40-digit randomly generated password...

(page 2) 33 comments
sorted by: hot top controversial new old

A company I used to work for is big enough that everyone reading this has heard of it. They had this wonderful security nightmare going on:

When you were hired, the company would issue your user credential with a standard password that was "CompanyName1" and require you to immediately change it at first logon. Everyone knew this password because everyone got it when they were hired.

Password policy required everyone to reset their password every 60 days. Not the worst ever but still pretty aggressive. And with the rise of all the mobile devices connecting with your corp account it was getting to be a worse and worse experience.

Can you guess yet how these two policies are linked in my story?

Well, some of the C-Suite executives didn't have time for any of these security shenanigans. So they would have their executive support person log into an administrative console and reset the exec's password every 59 days to the same value that it currently had, thereby bypassing the password re-use filter.

That value they were continuously setting was... "CompanyName1"

I know of at least two executives that were doing this while I worked there.

load more comments (1 replies)
[-] weker01@sh.itjust.works 14 points 1 day ago

Extremely limited password length. I think it was around 6 or 8 characters. Exactly! So every password was the same length.

No other requirements. The best part? It was a bank. But not a customer facing service.

[-] Kanzar@sh.itjust.works 8 points 1 day ago

My bank had a limit of six characters, for the customer facing login. Oops.

[-] coaxil@lemm.ee 3 points 1 day ago
[-] Kanzar@sh.itjust.works 4 points 1 day ago
[-] coaxil@lemm.ee 1 points 1 day ago

Haha knew it. Redic parameters

[-] joenforcer@midwest.social 2 points 1 day ago

Not sure but I think Schwab did it too.

load more comments (1 replies)
[-] TootSweet@lemmy.world 14 points 1 day ago* (last edited 1 day ago)

12 characters, upper/lower/special requirement, and no more than two occurrences of the same character together. That's FedEx.

Two other thoughts on the topic:

  • Websites/apps/etc should always list their password requirements on the login page to make it easier to determine what password you used for the site in question.
  • There are plenty of websites where I literally log in only by using the "forgot password" flow because their password requirements are so ridiculous.
[-] lemmyng@lemmy.ca 15 points 1 day ago

"Password must contain letters numbers, and at least one of these special characters."

Turns out, half of those special characters weren't allowed 🫠

[-] Boomkop3@reddthat.com 7 points 1 day ago

Facebook got caught having a flat text file being send around between employees to make accessing data easier. That text file contained tens of thousands of peoples username and password.

Why? Facebook being facebook I guess

[-] Soulifix@kbin.melroy.org 1 points 21 hours ago

Any service that says I must have a 12 or 14 string password, combined with symbols, numbers and letters.

Do you know why, I have to keep resetting my password, services that have this dumb requirement? Because your fucking requirements are absurd and unnecessary. I don't have the mental capacity to care to remember that long of a password. I have to have a document now of all of the passwords I have so it's not forgotten. I have to have browsers autofill for me because of this shit.

In a perfect world, 6 - 8 string passwords would suffice and lots of emphasis on symbols and numbers at the very least. The longer you try making the characters of a password, the chances of forgetting increases.

Flickr does this. Some of the portals to my apartment portal does this. Portals to some of my medical information does this. It's fucking bullshit. StateFarm does this too.

load more comments (4 replies)
[-] qantravon@lemmy.world 8 points 1 day ago

Most absurd was from a job I had in college. This was the password to log into an ancient dumb terminal (literally a monochrome black and green display) on a local-only network that only handled our time clock.

Requirements:

  • 8 characters exactly
  • You supply the first 4, the system generated the last 4
  • I can't remember if it allowed numbers, but there were definitely no special characters and I think it was also case-insensitive

Required to change password every 30 days.

[-] Dagwood222@lemm.ee 10 points 1 day ago

[offtopic?]

Debbie's password is "PlutoGoofyMickeyMinnieDaffyBugsThorLosAngles"

She was told that the password needed seven characters and a capital.

[-] 667@lemmy.radio 9 points 1 day ago

Except Sacramento is the capital of California, Debbie gonna struggle

[-] Dagwood222@lemm.ee 3 points 1 day ago

Los Angeles is considered the Movie Capital of the World.

Checkmate, liberal!

Nope, that's Hollywood! Checkmate, sovcit!

[-] bjoern_tantau@swg-empire.de 4 points 1 day ago

Well, they certainly managed to get her to make a strong password.

[-] Susaga@sh.itjust.works 1 points 1 day ago

What a strange choice to have 6 cartoon characters and a Norse god.

[-] TootSweet@lemmy.world 3 points 1 day ago

/c/dadjokes is over there ->

[-] Boomkop3@reddthat.com 6 points 1 day ago

It happens a bit too often that I make an account somewhere with a long, generated password and then when I log in it throws errors at me.

But a few times a website didn't just show me an error, I got the whole crash dump including their encryption approach and versioning

[-] otp@sh.itjust.works 8 points 1 day ago

Anything that requires regular password resets. It's fine if it's changed on the site and in the user's vault automatically, but if a user has to type in their password with any sort of regularity, it's a recipe for disaster to require regular changes.

People write predictable or formulaic passwords, or just end up resetting their password more often than necessary because they forgot it (making them more susceptible to phishing).

[-] Susaga@sh.itjust.works 2 points 1 day ago

There was an episode of Elementary where they were able to find the victims password on a post-it note, because the company requires a new password every month and he didn't want to remember a new one that often.

[-] shasta@lemm.ee 2 points 23 hours ago

Very common

[-] otp@sh.itjust.works 1 points 21 hours ago

It's the worst when they do that and have difficult restrictions on passwords.

One place I worked at had limits like "no more than two letters back-to-back", "no more than two numbers back-to-back and no sequential numbers".

The rules were available on the password reset screen.

The minimum was only something like 8 characters, so I have to wonder how many people had a1b2c3d? for a password.

Feed those rules to a password cracker and it'd be able to get in easily.

To their credit, I think they did support passwords that were maybe 64 characters long. But after they introduced those weird requirements (probably because some VIPs had stupid passwords like their names + birth year?), I just started hitting the character minimum because I'd have to manually type it in at least once.

[-] undefined@lemmy.hogru.ch 2 points 1 day ago

I memorized a handful of randomly generated passwords in high school (around 2005) and never looked back.

These days I use a password manager, but for semi-low security stuff (on my LAN) I use one, for my Apple account a long combination of three. And that’s it! The password manager is where it’s at.

Just one of my passwords was leaked in data breach (from back when I was younger and recycled passwords) so that one’s out, but otherwise I’m doing pretty well with the memorized randomly generated passwords.

[-] Treczoks@lemmy.world 2 points 1 day ago* (last edited 1 day ago)

I needed to get a certificate for digitally submitting my taxes. This, of course, requires me to set a password for it. The tax office' web site lists a number of requirements and rejects any password that does not match those (so it said). So far, so good, the usual stuff, lower and upper case, numbers, special characters, minimum lenght. No surprises there.

For one of the "special characters" I used "ö" (umlaut o), which is a normal character in my language (which is the same as the tax offices, so they should be aware of those). The web site filter happily accepted this password containing the "ö". But the back engine got a severe case of digital diarrhea from it. I had to clear my caches and cookies to completely re-starting the application process.

Another password SNAFU I had many years ago in a place using TN3270 terminals. To those who have never seen such a thing, it is a so-called "smart terminal". It does not send and receive single characters like a telnet or SSH session, but the host sends a mask to the terminal, defining fields that can be filled out, and with a "send" or "function" key (IIRC) you could send the data back. Those fields had fixed lengths, of course. You might guess the problem...

So the login screen had two fields of eight characters each: "Username" and "Password". I entered the credentials I have been given and sent them. The first thing I did was to select "change password". It opened a form with three fields: "old password", "new password", and "repeat new password". Nothing odd about that, but the fields had twelve characters. So, not knowing the particulars of that system (I was used to UNIX style terminals back then), I entered a new password that was longer than eight characters. Guess what? I logged out, I tried to log in, I was stuck. I had to ask my admin to reset my password. And had found the first of many, many bugs in that system.

[-] Railing5132@lemmy.world 4 points 1 day ago

I've encountered a few sites that restricted repeating or sequential characters. Of course told after failing the first creation attempt. Makes things like randomly generated passphrases fun to figure out. Particularly when their idea of "sequential" involves both in alpha/numerical order, but also adjacent spacing on the (assumed?) qwerty keyboard!

load more comments
view more: ‹ prev next ›
this post was submitted on 09 Jan 2025
66 points (100.0% liked)

Ask Lemmy

27391 readers
888 users here now

A Fediverse community for open-ended, thought provoking questions


Rules: (interactive)


1) Be nice and; have funDoxxing, trolling, sealioning, racism, and toxicity are not welcomed in AskLemmy. Remember what your mother said: if you can't say something nice, don't say anything at all. In addition, the site-wide Lemmy.world terms of service also apply here. Please familiarize yourself with them


2) All posts must end with a '?'This is sort of like Jeopardy. Please phrase all post titles in the form of a proper question ending with ?


3) No spamPlease do not flood the community with nonsense. Actual suspected spammers will be banned on site. No astroturfing.


4) NSFW is okay, within reasonJust remember to tag posts with either a content warning or a [NSFW] tag. Overtly sexual posts are not allowed, please direct them to either !asklemmyafterdark@lemmy.world or !asklemmynsfw@lemmynsfw.com. NSFW comments should be restricted to posts tagged [NSFW].


5) This is not a support community.
It is not a place for 'how do I?', type questions. If you have any questions regarding the site itself or would like to report a community, please direct them to Lemmy.world Support or email info@lemmy.world. For other questions check our partnered communities list, or use the search function.


6) No US Politics.
Please don't post about current US Politics. If you need to do this, try !politicaldiscussion@lemmy.world or !askusa@discuss.online


Reminder: The terms of service apply here too.

Partnered Communities:

Tech Support

No Stupid Questions

You Should Know

Reddit

Jokes

Ask Ouija


Logo design credit goes to: tubbadu


founded 2 years ago
MODERATORS