@damngoodtech @dumbpasswordrules Mathematically correct but functionally wrong. The "best case" password gets worse, but both the worst case and average case get better. Since the best case password is still definitley strong enough under most "complex" schemes, it still meets the goal of better passwords.
That's excluding ridiculous rules like max lengths, of course. And that's not to say there isn't a way to increase password security in a way that isn't infuriating to the humans using them.
This dumb password rule is from Cigna.
A max of 12 characters... Can't handle most symbols (only 5 supported). At least they have two factor auth via email or sms **sigh**
https://dumbpasswordrules.com/sites/cigna/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
You ever have a #pentest so bad the only real recommendation you can give is "Try another line of work, #webapp #development is not for you."?