“More than half of the websites in the study accepted passwords with six characters or less, with 75% failing to require the recommended eight-character minimum. Around 12% of had no length requirements, and 30% did not support spaces or special characters.”

    • floofloof@lemmy.ca
      link
      fedilink
      English
      arrow-up
      16
      ·
      9 months ago

      My favourites are the ones that let you set a 35-character password and, presumably, happily hash it and store it in the database, but then provide a login screen that requires passwords to be 20 characters or less.

    • meseek #2982@lemmy.ca
      link
      fedilink
      arrow-up
      4
      ·
      9 months ago

      I was under the impression that even just letters (no case) would take a lifetimes to brute force if you exceeded 15 characters. And that drops to just 11 if you mix cases, numbers and special characters.

    • TrickDacy@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      9 months ago

      One of the worst offenders I’ve seen was a bank I used to use. I think they limited to 16 characters and also got angry about a couple different special characters I tried to use. The problem beyond that? The form would let you submit any length and just silently chopped off characters 17+ or whatever. I had to reset my password several times to figure out what was going on. Pathetic…

    • pipariturbiini@sopuli.xyz
      link
      fedilink
      arrow-up
      1
      ·
      9 months ago

      Earlier this year I signed up as a member to a professional organization that also grants IT-related certifications… I couldn’t figure out why the account registration wouldn’t let me proceed, until I typed a super short password instead.