Dumb Password Rules

@dumbpasswordrules@infosec.exchange
1,007 Followers
0 Following
509 Posts

I'm a bot posting random sites from https://dumbpasswordrules.com.

Created by https://fosstodon.org/@duffn.

Also posting on Blue Sky at https://bsky.app/profile/dumbpasswordrules.bsky.social.

This dumb password rule is from Estheticon.

- At least 8 characters but limited to 20 characters at max
- At least 1 digit
- At least one letter (just a letter in general, no specific casing required)
- No special characters at all

https://dumbpasswordrules.com/sites/estheticon/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Estheticon - Dumb Password Rules

- At least 8 characters but limited to 20 characters at max - At least 1 digit - At least one letter (just a letter in general, no specific casing required) - No special characters at all

This dumb password rule is from IKEA.

Dumb restriction for consecutive similar characters. Wonder if someone got more that 2 identical characters in their name then
it won't allow you to even use name in password.

Password must contain:
- 8-20 characters
- **No more than 2 identical characters in a row**
- A lowercase letter (a-z)
-...

https://dumbpasswordrules.com/sites/ikea/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

IKEA - Dumb Password Rules

Dumb restriction for consecutive similar characters. Wonder if someone got more that 2 identical characters in their name then it won't allow you to even use name in password. Password must contain: - 8-20 characters - **No more than 2 identical characters in a row** - A lowercase letter (a-z) - An uppercase letter (A-Z) - Number or special character

This dumb password rule is from Sprint.

Sprint "upgraded" their security and disallow special characters.

https://dumbpasswordrules.com/sites/sprint/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Sprint - Dumb Password Rules

Sprint "upgraded" their security and disallow special characters.

This dumb password rule is from Gigabyte RMA system.

Your password must contain:
Between 8-12 characters
An upper case letter (A, B, C, etc.)
a lower case letter (a, b, c, etc.)
A number (1, 2, 3, etc.)
A symbol (-, ~, !, #, $, %, &, (, ), +, =, .)

https://dumbpasswordrules.com/sites/gigabyte-rma-system/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Gigabyte RMA system - Dumb Password Rules

Your password must contain: Between 8-12 characters An upper case letter (A, B, C, etc.) a lower case letter (a, b, c, etc.) A number (1, 2, 3, etc.) A symbol (-, ~, !, #, $, %, &, (, ), +, =, .)

This dumb password rule is from Thames Water.

Can only use the "special" characters on that very limited list, excluding symbols so exotic as an underscore, even. This is despite their own strength checker saying the password is strong.

https://dumbpasswordrules.com/sites/thames-water/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Thames Water - Dumb Password Rules

Can only use the "special" characters on that very limited list, excluding symbols so exotic as an underscore, even. This is despite their own strength checker saying the password is strong.

This dumb password rule is from Blackrock.

They force you to enter a password that has 8, 9, or 10 characters, then
they lecture you on how to create a strong password.

https://dumbpasswordrules.com/sites/blackrock/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Blackrock - Dumb Password Rules

They force you to enter a password that has 8, 9, or 10 characters, then they lecture you on how to create a strong password.

This dumb password rule is from IBM TSO/E Logon terminal.

It might not be a web site, but that does not make it less dumb.
Since many don't know about IBM mainframes, it seems they don't think you need to up the policies.

Default old password policy is: 6-8 characters long, A-Z, 0-9

Over the last few years they have updated their policies a bit, but d...

https://dumbpasswordrules.com/sites/ibm-tso-e-logon-terminal/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

IBM TSO/E Logon terminal - Dumb Password Rules

It might not be a web site, but that does not make it less dumb. Since many don't know about IBM mainframes, it seems they don't think you need to up the policies. Default old password policy is: 6-8 characters long, A-Z, 0-9 Over the last few years they have updated their policies a bit, but due to many of their subsystems are incompatible, they can't enforce the new options for safer passwords.

This dumb password rule is from Turkish Airlines.

- Your password must consist of 6 digits
- Make sure that your password does not contain your date of birth or three consecutive digits...
- but two is OK, for sure.
- ... and that the same number is not repeated three or more times.
- but two times is probs OK

https://dumbpasswordrules.com/sites/turkish-airlines/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Turkish Airlines - Dumb Password Rules

- Your password must consist of 6 digits - Make sure that your password does not contain your date of birth or three consecutive digits... - but two is OK, for sure. - ... and that the same number is not repeated three or more times. - but two times is probs OK

This dumb password rule is from Vélib’ Métropole.

Your password must be at least 10 characters, with at least 1 uppercase character, 1 lowercase character, 1 number and 1 special character (only from this list: @, $, €, #, %, *, ., ;, !, ?).

You're not allowed to paste passwords.

https://dumbpasswordrules.com/sites/velib-metropole/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Vélib’ Métropole - Dumb Password Rules

Your password must be at least 10 characters, with at least 1 uppercase character, 1 lowercase character, 1 number and 1 special character (only from this list: @, $, €, #, %, *, ., ;, !, ?). You're not allowed to paste passwords.

This dumb password rule is from MKB NetBankár.

It only accepts lowercase letters, uppercase letters and numbers (any
other character counts as forbidden character).
Also, if your password contains any invalid character, it will get
marked as "Identical to the former 10 passwords".

To make it more fun, during the registration, it allows to se...

https://dumbpasswordrules.com/sites/mkb-netbankar/

#password #passwords #infosec #cybersecurity #dumbpasswordrules

MKB NetBankár - Dumb Password Rules

It only accepts lowercase letters, uppercase letters and numbers (any other character counts as forbidden character). Also, if your password contains any invalid character, it will get marked as "Identical to the former 10 passwords". To make it more fun, during the registration, it allows to set a 24 characters password to login to their website. Once you try to login with the password, it will say that the maximum length accepted is 16 characters. What actually happens, is that they let you insert 24 characters during registration, but only the first 16 will get actually used as password.