Office365 doesn't support passwords > 16 characters in length. WTF.
Office365 doesn't support passwords > 16 characters in length. WTF.
Also Paypal doesn't support any form of secure OTP.
Also, Paypal forces security questions on the user.
In other news, my Hearthstone account has better security than my money.
https://github.com/jleclanche/python-bna
See the README for usage :)
This should help you to have a backup next time you get locked out!
The official authenticator also displays a backup code which it tells you to keep a copy of somewhere safe...
Be between 8 and 10 characters long (with no spaces)
Contain only numbers and letters (no characters like @*? etc).
Start with a letter.
Not contain 3 numbers in a row.
But still...
That is a requirement in a ton of places. Try creating an Oracle database user, and have the password start with a number. To be fair it's documented that it won't work, but Oracle won't stop you from doing it, so you end up with an unusable account.
So for example, a bcrypt output might look like: $2a$12$2zuYZPvIlfC.L84k0oWZR.8yGd62dPkhoyg4aEC6TzGl7aASTw5F.
You can bypass the limit with ADFS.
Humans are bad at remembering most things. The more entropy there is, the more difficult it tends to be for us to remember.
The way for increasing password entropy, whilst lowering the human bound, tends to be by utilising things humans find easy to remember, but computers find difficult to randomly/brute-force solve.
That usually requires a longer password.
You can sort-of bypass the human memory problem by using password managers, but they have their own set of problems (mostly usability), and assuming people actually use them is an assumption too far in most cases.