This dumb password rule is from Aetna Health Insurance.

- Password cannot be longer than 20 characters
- Password cannot have spaces and more 2 characters repeated in a row
- Password cannot have user's first name, last name or username

https://dumbpasswordrules.com/sites/aetna-health-insurance/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Aetna Health Insurance - Dumb Password Rules

- Password cannot be longer than 20 characters - Password cannot have spaces and more 2 characters repeated in a row - Password cannot have user's first name, last name or username

This dumb password rule is from Minnesota Unemployment Insurance.

Locked to *exactly* 6 chars, alphanumeric only, not special chars.

https://dumbpasswordrules.com/sites/minnesota-unemployment-insurance/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Minnesota Unemployment Insurance - Dumb Password Rules

Locked to *exactly* 6 chars, alphanumeric only, not special chars.

This dumb password rule is from BBVA.

Username is your national ID (easy to find) and your password must have up to **6** alphanumeric characters only.
For a bank account with all your money in one of the largest financial institutions in the world.

https://dumbpasswordrules.com/sites/bbva/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

BBVA - Dumb Password Rules

Username is your national ID (easy to find) and your password must have up to **6** alphanumeric characters only. For a bank account with all your money in one of the largest financial institutions in the world.

This dumb password rule is from Getin Bank.

The new password should contain at least 10 and a maximum of 20 characters.
The password must contain at least one upper case letter, one lower case
letter and one number. The password cannot contain non-ASCII Polish alphabet
characters, special characters `&<'"` or spaces.

https://dumbpasswordrules.com/sites/getin-bank/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Getin Bank - Dumb Password Rules

The new password should contain at least 10 and a maximum of 20 characters. The password must contain at least one upper case letter, one lower case letter and one number. The password cannot contain non-ASCII Polish alphabet characters, special characters `&<'"` or spaces.

This dumb password rule is from ADP.

Forced to change the password during the first login. At least they
could use proper grammar in their rule list.

https://dumbpasswordrules.com/sites/adp/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

ADP - Dumb Password Rules

Forced to change the password during the first login. At least they could use proper grammar in their rule list.

This dumb password rule is from Dnevnik.ru.

Silently (sic!) trim password to 30 symbols.

That causes the stupid case when you could successfully registrate an account with password length of 52 and can't login with the password.

https://dumbpasswordrules.com/sites/dnevnik-ru/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Dnevnik.ru - Dumb Password Rules

Silently (sic!) trim password to 30 symbols. That causes the stupid case when you could successfully registrate an account with password length of 52 and can't login with the password.

This dumb password rule is from Taleo.net.

Oracle Taleo is one of those old-school enterprise Applicant Tracking
Systems (ATS) that half the corporate world still uses even though
everyone hates it.

https://dumbpasswordrules.com/sites/taleo-net/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Taleo.net - Dumb Password Rules

Oracle Taleo is one of those old-school enterprise Applicant Tracking Systems (ATS) that half the corporate world still uses even though everyone hates it.

This dumb password rule is from Express Energy.

Retail Electricity Provider (REP) participating in ERCOT.

Minimum 6, maximum 10. Stated requirement of numbers and letters, but special characters are accepted.

https://dumbpasswordrules.com/sites/express-energy/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Express Energy - Dumb Password Rules

Retail Electricity Provider (REP) participating in ERCOT. Minimum 6, maximum 10. Stated requirement of numbers and letters, but special characters are accepted.

This dumb password rule is from Bank Millennium.

Passwords limited to 8 digits.

https://dumbpasswordrules.com/sites/bank-millennium/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Bank Millennium - Dumb Password Rules

Passwords limited to 8 digits.

This dumb password rule is from myezyaccess.com patient portal system.

12-character maximum password length. This is not a single website but a patient portal system used by hundreds of medical facilities via subdomains, with password policy apparently being consistent for all sites.

https://dumbpasswordrules.com/sites/myezyaccess-com-patient-portal-system/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

myezyaccess.com patient portal system - Dumb Password Rules

12-character maximum password length. This is not a single website but a patient portal system used by hundreds of medical facilities via subdomains, with password policy apparently being consistent for all sites.