The first piece of advice we give whenever the topic of passwords comes up is to adopt a password manager. All you need is one very strong master password to unlock the vault, and let the program generate the rest with combinations that would be a nightmare for brute-force attacks. However, many sites out there don't recognize the flexibility of managers and force users to apply very clumsy rules to their personal passwords. A GitHub section called Dumb Password Rules serves as a hall of shame for those sites.
The Problem with Weak Passwords
One of the worst things we can do is reuse passwords across different services. Even I haven't escaped the convenience of using the same password on four or five different platforms, but with massive cyberattacks leaking millions of passwords at a time, that practice is an invitation to disaster. Then there are weak passwords. The years go by, but 123456 keeps topping all the lists as the worst.
How Ridiculous Rules Undermine Security
We also have to admit that many sites hinder password creation with their ridiculous rules. From 8 to 13 characters, no spaces or symbols, no repeated letters or sequential numbers... the more absurd those rules, the more users are tempted to take shortcuts and ignore the security of their accounts.
The 'Dumb Password Rules' Repository
A GitHub profile called 'Dumb Password Rules' is dedicated to celebrating these sites and their absurd password rules. The list has dozens of entries, and users can make their own contributions. There are some very high-profile names. For example, Apple imposes basic restrictions (8 or more characters, uppercase and lowercase, and at least one number), but doesn't warn you that using three identical characters in a row is forbidden until you try it.
Battle.net is another catastrophe, with 8-16 characters, at least one number and one letter, no special characters, and no recognition of uppercase. One of the worst is amelie.fr, the health and social security portal of France. Minimum 8 characters, maximum 13, all digits, no birth dates or repeating the login, sequential sequences forbidden (e.g., 567), and no repeated digits (33, 77, etc.). A brute-force attack would eat that password in minutes.
A Long List of Offenders
BBVA, Best Buy, Movistar, Origin, PayPal (!), Sprint, T-Mobile, Ubisoft, Walmart, dozens of banks... I just hope administrators pick up the gauntlet, understand that many of these rules are counterproductive, and enable the use of passwords more aligned with the managers of the moment.
Official site: Click here