“More than half of the websites in the study accepted passwords with six characters or less, with 75% failing to require the recommended eight-character minimum. Around 12% of had no length requirements, and 30% did not support spaces or special characters.”

  • Technus@lemmy.zip
    link
    fedilink
    arrow-up
    31
    ·
    8 months ago

    It’s 2023 and I still see signup forms that are like “must have at least one of each: number, lowercase letter, uppercase character, special character (but not , . " & / + < > {} [] )”

    That, plus no single sign-on (privacy issues aside) and login flow design so bad that password managers don’t know what the fuck is going on, and it’s no wonder password security is still a huge issue.

    • meseek #2982@lemmy.ca
      link
      fedilink
      arrow-up
      10
      arrow-down
      1
      ·
      8 months ago

      My old domain registrar set an 7 character limit, no special characters of any kind. Just numbers and letters. This was back in 2020 🫠

    • floofloof@lemmy.ca
      link
      fedilink
      English
      arrow-up
      16
      ·
      8 months ago

      My favourites are the ones that let you set a 35-character password and, presumably, happily hash it and store it in the database, but then provide a login screen that requires passwords to be 20 characters or less.

    • meseek #2982@lemmy.ca
      link
      fedilink
      arrow-up
      4
      ·
      8 months ago

      I was under the impression that even just letters (no case) would take a lifetimes to brute force if you exceeded 15 characters. And that drops to just 11 if you mix cases, numbers and special characters.

    • TrickDacy@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      8 months ago

      One of the worst offenders I’ve seen was a bank I used to use. I think they limited to 16 characters and also got angry about a couple different special characters I tried to use. The problem beyond that? The form would let you submit any length and just silently chopped off characters 17+ or whatever. I had to reset my password several times to figure out what was going on. Pathetic…

    • pipariturbiini@sopuli.xyz
      link
      fedilink
      arrow-up
      1
      ·
      8 months ago

      Earlier this year I signed up as a member to a professional organization that also grants IT-related certifications… I couldn’t figure out why the account registration wouldn’t let me proceed, until I typed a super short password instead.

  • dhtseany@lemmy.ml
    link
    fedilink
    arrow-up
    10
    ·
    8 months ago

    Cool now talk about how shitty banks block auto-fill on their login forms which keeps you from using it with your password managers. Oh, and no, you can’t paste into those fields either cuz “security”.

  • inetknght@lemmy.ml
    link
    fedilink
    arrow-up
    9
    ·
    8 months ago

    If a website requires so few characters that I have to create custom rule in my password manager for it… then it’s a website I’m strongly inclined not to use.

    Sadly, a lot of these websites deal with finances or employment.

      • wincing_nucleus073@lemm.ee
        link
        fedilink
        arrow-up
        1
        ·
        7 months ago

        you know what’s funny. in paypal you are not even allowed to make a secure password. they have a short character limit.

        • Pantherina@feddit.de
          link
          fedilink
          arrow-up
          1
          ·
          7 months ago

          Yesss my shortest Password. Fuck Paypal I only have it for weird stuff and that Indian Developer that still maintains LineageOS Android 14 for my Nokia phone

  • AutomaticJack@beehaw.org
    link
    fedilink
    arrow-up
    5
    ·
    8 months ago

    I’ve come across a few sites that require one upper case, one number and one symbol (from a short list). Not at least one of each, no no, precisely one of each. One site even forced the password length to be exact -_-