Git Product home page Git Product logo

dumb-password-rules's People

Contributors

28 avatar carbontwelve avatar daethnir avatar danielcraigie avatar dawnerd avatar dependabot[bot] avatar duffn avatar duhow avatar dvdmuckle avatar fezvrasta avatar ghs avatar h4ckninja avatar kel avatar koenhoeijmakers avatar marianoju avatar mburrough avatar natemacinnes avatar nicolasdanelon avatar nschrader avatar rillig avatar rpdelaney avatar scrabill avatar seggewiss avatar shreyashmohadikar avatar smtchahal avatar sn0opy avatar sophiedeziel avatar txtsd avatar wwestrop avatar yawnoc avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

dumb-password-rules's Issues

Add Comcast

don't have a screenshot ATM, but as of yesterday, requirement is 8-16 characters

Hargreaves-Lansdown bad username rule

Ok this isn't an issue but I'm too lazy to do a pull request. And I have a question - can I create a new section for bad username rules? Seriously Hargreaves-Lansdown:

wtf

They have the same rule for their passwords, unsurprisingly. Ugh.

Thank you for this compilation - now what to do...

I am thankful that so many people have been willing to create this list.

Thank you!

We now have an ever-growing list of those that have it wrong.
And it appears from this list that most sites have it wrong.

Here's a challenge:
Tell us your preferred password policy that:

  • balances usability with security, and
  • supports popular password managers and generators, and
  • will work at least on popular desktop and mobile browsers and in mobile apps.

Not kidding! Come up with a "good" password policy - so at least when one of these sites fixes their password policy, you can kindly and unarguably remove them from the shame list.

You will be doing the world a great service! Then at least if everyone adopts your policy, everyone will have better passwords, and people can use passwords that follow a pattern even though not the same since everyone reading this knows you SHOULD (RFC 2119) use a different password everywhere.

Once you come up with that, comb through your list again and see if any site is already compliant.

Thank you - sincerely - thank you!

Transfer repository to organization

Iโ€™ve made the dumb-password-rules organization as it seems a few people are willing to work on the repository and this may be a better way to handle collaborators. I will transfer ownership to the org and add @nitrocode and @dawnerd as members to assist in the next phase of this project (#114).

Remove OVH

The OVH 2FA example is using a numerical input field <input type="number"/> which automatically causes some (but not all) browsers to include the lamented increment/decrement buttons.

2FA algorithms that use numbers are common (standardized in RFC 6238) and it makes sense to use type="number" in these cases (for example, this will show a numerical keyboard on phones instead of a QWERTY keyboard).

So OVH is doing 2FA exactly right and should be removed from the list.

Add Coventry Building Society

Coventry Building Society in the UK, has to be between 6 and 10 characters, can't contain any punctuation and you have to give characters from it on the phone to confirm identity!

Your password must be between 6 and 10 characters long and must not use spaces, commas or any other punctuation.

Screen Shot 2019-07-31 at 18 41 29

Appologies, not able to create a PR.

Amazing :)) ranked based on alexa

Amazing, thank you to be a voice of my frustrations.

It will be so so cool, if u roughly ranked them also based on alexa ranking....

Add IRS

The US IRS website has some dumb rules.

Facebook bizarre password "bypasses"

Facebook passwords do not have to be exactly correctly and can be slightly bypassed if you are close enough. This greatly reduces the entropy of passwords in certain cases (especially short ones).

It seems that:

  • they are case insensitive almost all of the time
  • adding an extra character to your password will still result in the password being accepted
  • the username/email can be up to 3 characters off and still be accepted
  • unknown other conditions

Facebook does employ a trust engine to allegedly require stricter checking from suspicious logins, but even if you set your VPN to say Malaysia / change your user-agent to something random it almost never goes off.

My understanding is this is designed to facilitate convenient/faster logins for users...

NOTE: anyone can take this issue and run with it, but if not I'll just put in a pull request in a few days

Extended with dumb-email-rules or to dumb-form-rules?

I noticed #70 for bad username rules. Would you be interested in websites with bad email rules too?

The one rule that annoys me with email is when they prevent you from signing up using the plus character. e.g. you can filter your email better in gmail if you add a + and then some string to your email like [email protected] will get sent to [email protected] but lots of websites will prevent the plus character.

If you're willing to extend it to bad emails, it may not be too much of a stretch to extend this as bad-form-rules or bad-login-rules to keep it more generic.

MKB Bank (Hungary)

image

The website doesn't allow "some characters", actually it doesn't allow any special character, for security, logically.

Add dell.com

20 character max, I think? The error message says follow the rules and there are no rules about a max number of characters.

Platforms other than websites?

The Internet is not only the web (even though there's a lot of web). I've got an offender they might warrant an entry, even though they're not a website: QuakeNet's IRC services.

Maximum of 10 characters. Bonus points: stored in plaintext!

Not a website though, should I add this? If not, how should I make the relevant screenshots?

Apple iCloud max of 32 characters

Apple only allows 32 characters maximum for iCloud passwords. Leaving this issue here for anyone to take. If not I'll put in a PR in a couple of days.

University of Notre Dame

Password must be 16 characters or longer. Only applies when you change your password. Evidently, shorter passwords are equivalently secure, provided that you had the password before the new requirements were set up.
Notre Dame Password Stupidity

AOL Comment misleading

In the section for AOL, it says

Oh, and thanks for restricting one of the most common special characters!

However, the listed requirements don't appear to restrict any special characters? Rather, it encourages the use of special characters !@.# saying

Strong passwords include special characters (!@.#)

Limiting max length to 16 is still dumb but I'm not seeing any issues with special characters here.

Add table of contents for increased shaming

Companies with names in the middle of the alphabet get to hide in relative anonymity. If you convert this README to a markup language that supports a table of contents (e.g. reStructuredText or Org), their shame will be magnified.

Bank of America 20 chars max + other dumb things

Please see the below screenshot.
boa

Also if you go to this link and then inspect the source code of the page (ctrl+f for the word "consecutive" and it should bring you to the right point) you can verify these requirements are still in force.

Bestbuy

You can change your password to be anything (Excellent!) but when you try to log back in you're locked out. Seems to happen when a password is really long.

I have a 64 character password containing symbols and all the fun stuff generated through 1pass. On login: Sorry, a problem occurred during sign in. Please try again.

Add Delta Airlines

Delta recently reduced account security by implementing some pretty dumb password rules.

dk8h_yvu8aalznf

PayPal max length

I'm not sure if they fixed it, but last time I entered a password generated by 1Password that was too long, it allowed me to change it, but when I tried to login it said that it was wrong.

Maybe worth it to verify it and update accordingly.

Add MLB.com

They only allow 6-15 characters with no special characters.

Update Williams-Sonoma after updated error message is public

Yeah that message is uh not good. It's been like that for more-or-less 8 years, good time to tidy up.

This'll be modified in an update post-holiday, The password is invalid. Make sure it does not contain any of the following characters: { } | ~ [ ], here and in other places this message format appears. I'll pull request against this once change is public. Thanks for attention to detail.

AWS only allows 1 Yubikey

AWS ruins the idea of Yubikeys for many users.

Almost all services allow multiple Yubikeys. One to use and one to say put in vault or a secure location for backup. Because AWS allows only one, you better not ever lose that thing or you're out of luck. AWS can restore access to your account I will say, but obviously such a process is slow and involves many checks.

NOTE: anyone is free to take this and create a PR. Please also mention that the "Password Policy" for the AWS IAM service is terrible! Only 6 chars minimum lol.

Izly should not be included

No reason to include Izly here. 6 number pin is common and used in many bank websites. If you want to include Izly you should then include all (well most) bank websites.

About the fact that it is not translated in French maybe you should first try to learn how to use a web browser :
screen shot 2016-12-13 at 15 08 40

About the fact that your account can be blocked after too many login failed attempts, that is the way every internet accounts work.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.