> Password Rules:
> 1) At least 8 characters long.
> 2) Must contain at least one numeric and one special character (!@#$%&). (and asterisks, which is ruining formatting here)
> 3) At least one uppercase and at least one lowercase letter.
My standard password pattern* has a different special character in it, so now I'm locked out for 24 hours because I can't remember what substitution/alteration I made! It kills me when "password requirements" purportedly for security are more restrictive on one site than the majority of others. I also infer the sites are rarely updated.
*I'm implementing Dashlane at work. To date, having a unique password for every site/service has felt secure.