Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is far from the worst offender.

Banks are typically the worst. All sorts of gimmicky password requirements. 8-12 characters. Must have one capital letter. Must have one number. No special symbols.

So "I can't believe it's not butter!" won't work, yet that would probably be a pretty secure password, and be entirely rememberable. In fact I could come up with a silly pun-filled sentence for each site I visit and make passwords fun again.



The poor state of bank passwords is fresh in my head from working on taxes tonight. It's kinda sad that the message boards I use for non-sense are probably more secure than my banks with respect to password handling.

That said, I don't think Stardock gets a free pass just because a lot of banks suck at it.


Nobody gets a free pass. Didn't mean to imply that. They all suck, it's just a matter of venting :)


My favorite is the eAPIS password requirements:

https://eapis.cbp.dhs.gov/help.html#a7

   Your password:

   must start with a number and be between eight and twelve characters in length, and
   must contain at least one of the following special characters:
   Cannot include your Sender ID, and
   Cannot repeat any character consecutively more than two times.


That would make an excellent passphrase

It's funny that the descriptions of password requirements would make much stronger passwords than any password a reasonable person would ever use.


American Express used to require 6-8 alphanumerics. No more, no less. Fortunately they've upped this to... I think something like 20 characters.

Look, I get that there are other safety factors (I pray) in place to prevent someone from hacking my account (most commonly in the form of login-attempt limits), but that's absolutely no reason to stop me from making my password longer and more complex. If I want my door to have a deadbolt _and_ a chain lock I expect a damn good explanation if someone tells me I can't.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: