Welcome to password creation hell
devonhomechoice.com
devonhomechoice.com
Some dev has been having fun with this while all the product people are away. As a creator of useless side projects, I can relate.
This amazes me a lot more than a ridiculous password scheme. You can always come up with a justification for a stupid password scheme. But there's no justification for "I don't know how sessions work" after 20 years of web development history. It was the #1 most frequent developer mistake IN 1999.
https://www.nngroup.com/articles/the-top-ten-web-design-mist...
I used the following Java code, which may be flawed, to count:
public static void main(String[] args) throws Exception{
int count=0;
int[] digitCount=new int[10];
mainLoop:
for(int i=0; i<=999999999; i++){
Arrays.fill(digitCount,0);
digitCount[i / 1 %10]++;
digitCount[i / 10 %10]++;
digitCount[i / 100 %10]++;
digitCount[i / 1000 %10]++;
digitCount[i / 10000 %10]++;
digitCount[i / 100000 %10]++;
digitCount[i / 1000000 %10]++;
digitCount[i / 10000000 %10]++;
digitCount[i / 100000000 %10]++;
int differentNumbers=0;
for(int index=0; index<10; index++){
if(digitCount[index]>3){
continue mainLoop;
}
if(digitCount[index]>0){
differentNumbers++;
}
}
if(differentNumbers>4){
count++;
}
}
System.out.println("count: "+count);
}There's 10 valid ways to choose the first digit. You either repeat that digit one or zero times. If once, there are 8 ways to do this, and then you have the same sub-problem except with 9 remaining characters to use and 7 remaining places to fill. If none, there's one way to do it, and then you have the same problem except with 9 remaining characters to use and 8 remaining places to fill.
A bit silly granted, but it'll let you ditch half the zero-padding. (Only half, but if they're going to be repeated n times, it might be worth it).
> Your password must be 8 to 20 characters and may include upper or lowercase letters (A-Z and a-z), numbers (0-9), spaces (except at the beginning or end), and special characters. You must use at least one letter and one number. You cannot use the same character in four or more consecutive positions (for example, AAAa is valid, but AAAA is not valid) and you cannot use four or more sequential characters, in ascending or descending order, in a row (for example, ABCD and 4321 are not allowed).
It almost feels like a riddle...
Because I have to choose a complicated password that I can't remember, every single time I go back (maybe twice a month) I pretty much have to use the password reset functionality and make another non-memorable password. Even setting up the password takes some thinking as you can read the requirements that you have to conform with. Ugh. It's pretty annoying.
$ pass insert adp
with cloud computing a security company recently has shown us if they can find a hole to get the files where systems store such information they can reverse most. there is a dearth of knowledge out there how each platform stores such data and finding an in is incredibly easy at the majority of companies
Talk about reduction of password entropy.
To change your Internet Banking password, please enter your current password and then enter your new password to confirm.
Password requirements:
Must be between 6 and 8 characters and can contain letters, numbers or both
Will be case sensitive so check your caps lock
Can't contain special characters (eg. $%&#) or spaces
Can't be your Customer ID
Can't contain consecutive numbers (eg. 123456)
Shouldn't contain part of your name, date of birth, drivers licence or anything that would be in your wallet Password needs a minimum of 10 digits.
Low and upper characters, at least 2 numbers
and could include special characters. These
chars are not allowed: ! & ' ` $ % ; § ~ ^ @
\ € ä ö ü ß. It will be checked against last
two former passwords and it couldn't be
include 3 or more identical characters.
Theres not many spacial characters left. Also this is a german University and äöüß are not allowed.https://www.ncsc.gov.uk/guidance/password-guidance-simplifyi...
> Your new password must contain 9 numbers, and include at least 4 different numbers but cannot include the same number more than three times.
> To create a new password you will need to confirm some basic personal details (name, date of birth and National Insurance number).
> These must match the details recorded on your Devon Home Choice application.
- At least 2 to 4 numbers will be reference to a specific year, such as the user's birth year or the current year, e.g. 17, 1965, 2017.
- As many as 3 to 4 numbers will be a predictable pattern, such as an incremented sequence or repetition of numbers not likely to be a birth year or of `2017`, e.g. `1234`, `987`, `1010`
Why is everyone assuming this means the password must only contain 9 numbers? I mean, it's very likely, but it's ambiguous enough that I was wondering if they accept other characters and want 9 numbers as well.
And then maybe have a brief explanation of what makes a password weak, but let the user decide if they want to get hacked or not.
If you can figure out what they use for user IDs (emails, or perhaps another 9-digit number), you'll own all these user accounts.
This is what happens when cleverness meets ignorance of security.
"
Your password must conform to the following rules:
- It must be exactly 6 characters
- The first character must be @ or #
- The second character must be a digit except 0.
- The third character must be a lowercase, uncommon letter. Uncommon letters are q, x and z.
- The fourth character may be any uppercase vowel, with the exception of U. Y is not considered a vowel.
- The fifth character must be a lowercase letter differing from the third character.
- The sixth character must be an underscore (_).
Your password must be changed after every third log-in. You may not use any of your previous ten passwords nor any password you have used in the past 180 days.
function isPasswordValid(pass){
//There's no way in hell they figured it out.
return false;
}