- Maximum length requirements (often secret until you try to put a password in)
- Requiring some symbols, but not others
- Silent truncation of the the password without telling you
- Failure because the password is too long, but the error says something else (like missing symbol)
This isn't just small unknown companies either. If you use a password longer than 32chars in Zoom when creating your account it just truncates the remaining without telling you. Login works on the websites, but if you try to login via the client it fails. If I manually backspace to 32chars it works. I tried to tell it to their US Twitter support and they just kept sending me a password reset link so I gave up (they're a bad company anyway [0]). Tmobile's website used to do the same thing, except worse because it would truncate on creation but not on validation.
How is this not standardized in some sane way?
An old credit union I was part of in NY (SEFCU) mandated passwords with exactly 6 characters. When I complained about this I was told it was secure because they forced one of the characters to be a symbol.
[0]: https://zalberico.com/essay/2020/06/13/zoom-in-china.html