Usernames removed to prevent brigading

  • mogranja@lemmy.eco.br
    link
    fedilink
    arrow-up
    40
    ·
    1 day ago

    I hate when websites have some weird rules for passwords, and show the rule when you are creating the password, but not when entering it. How am I supposed to remember the password must begin and end with a special character?

        • FooBarrington@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          6 hours ago

          I’ve literally never had an issue with password generation. Usually I generate 32 character passwords with all types of characters passwords on average expect. If a page has different rules, I just check the corresponding boxes in my password manager, and I get one that works for that site.

          • bestboyfriendintheworld@sh.itjust.works
            link
            fedilink
            arrow-up
            2
            ·
            3 hours ago

            Just yesterday my library required a new password. The password requirements were:

            • 8 to 18 characters
            • uppercase
            • lowercase
            • number
            • one of the 8 special characters listed

            When borrowing from the library physically, I need to enter this password on a touchscreen keypad. So no copy and paste from a password manager.

            They used to have birthdates as the assigned password for everyone. If you request a password reset, it resets to the birthdate. You have to change it on first login.

            A little better than before, but doesn’t feel secure.

            On the other hand, abuse is kinda difficult.

            For physically loaning books, you need the library card with its RFID chip. For anything digital, there’s no incentive or possibility for abuse really.

    • furry toaster@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      16
      ·
      edit-2
      3 hours ago

      and when the rule is also wrong example: password must contain special charcters

      the password in question contained : and ^

      if those aren’t special characters idk what is

        • topherclay@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          3 minutes ago

          “Punctuation yes, emoji no” sounds like something a grade school teacher would have embroidered on a throw pillow.

      • fibojoly@sh.itjust.works
        link
        fedilink
        arrow-up
        5
        ·
        8 hours ago

        I never get bored of discovering yet another software that gets broken because someome put a dollar sign in their password…

      • sus@programming.dev
        link
        fedilink
        arrow-up
        9
        ·
        edit-2
        21 hours ago

        maybe they were looking for extra special characters like 🁄 or ⶸ. Who am I kidding, RFC 1738 tells us that literally everything is unsafe and you know, we need to prepare for the inevitable occasion when the password somehow ends up inside an URL.

        The characters “<” and “>” are unsafe because they are used as the delimiters around URLs in free text;
        the quote mark (“”") is used to delimit URLs in some systems.
        The character “#” is unsafe
        The character “%” is unsafe

        It ends up with

        Thus, only alphanumerics, the special characters
        $ - _ . + ! * ’ ( ) ,
        are safe

    • AceOnTrack@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      11
      ·
      1 day ago

      Having to alter my one generic password I use for random ass website because there’s a stupid extra rule is usually annoying me enough that I don’t register lmao.