gJbleSgB_5Dx!l{*sX%L

WorriedCongested3Turkey

#bot #password #passphrase #infosec #opsec

This dumb password rule is from Synchrony Financial.

Financial services - where we don't allow you to create the strongest
password possible.

https://dumbpasswordrules.com/sites/synchrony-financial/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Synchrony Financial - Dumb Password Rules

Financial services - where we don't allow you to create the strongest password possible.

gnimKG4Px40\N0lnUGCO

SwizzleFamished6Macaw

#bot #password #passphrase #infosec #opsec

I got a notification today

Paraphrasing:

“Hey we got a breach. Your password was leaked crypted (not hashed) and they also got your full postal address. We recommend updating your password, but we took the website down for now.“

I can’t fault them for wanting to beef up their security… But the timing is not great. They also left up a probably very insecure web form to keep collecting leads on their front page.

#SecurityBreach #password

&%+F8L4\;bVIK{3"HO.6

NumberPrepay4Genre

#bot #password #passphrase #infosec #opsec

This dumb password rule is from Bank Leumi (Israel).

- Password consists of 6 to 12 characters
- Password contains only english letters and numbers without spaces.

https://dumbpasswordrules.com/sites/bank-leumi-israel/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Bank Leumi (Israel) - Dumb Password Rules

- Password consists of 6 to 12 characters - Password contains only english letters and numbers without spaces.

DeRV.nBKU)$[7~L3uecz

ObsessedAstute3Willed

#bot #password #passphrase #infosec #opsec

Tk>]uGaM5~>"-GI;3k{x

UnlinedOblong5Kilobyte

#bot #password #passphrase #infosec #opsec

Sampath Bank - Dumb Password Rules

So many rules!

Can there be a #password #hashing algorithm that considers the distance between each character key on a keyboard (of some specific layout, say QWERTY)? The difficulty of hitting the correct character on a small 26-key on-screen keyboard on my phone is making me think whether we should have a relaxed algorithm that gives some fault tolerance... (Surely it'll not be as secure, but it could allow longer passwords on phones.)