And they would almost certainly know the password rules, because anyone making an account would have to be told the rules in order to understand what was happening.

Unless the rules were unique and hidden for each user!

    User1: 1,3,7,10,12,15
    User2: 2,3,5,8,10,13
I think we’re on to something big.

It's complicated enough for people to remember 8 character long passwords, good luck with an additional level of complexity.

Each user could provide their own rules.

