Grinds my bloody gears.
What irritates me more is knowing that the people who implement those solutions are probably here. Shame on you, go back and fix it right now!
Login with your password. Site then responds that we emailed you a security code, but the security code expires in five minutes. Immediately below that, it notes that the email may take up to four minutes to send. From experience, I think the note about slow emails is accurate.
Who spent more than 30 seconds on that implementation thinking it was acceptable? Note that this is for a stupid intra-company fitness tracking thing (ie, I do not care at all about this data). Confirmation codes from my bank have a 30 minute window, but that is evidently too lax for step counting.
Now that whole site has the weirdest bugs. When I go to the mailbox, the site switches to some eastern european language. The things we do for cheap electronic components ...
'; DROP TABLE users; --
just for the lulz...
Oh, of course they truncate also the password confirmation field.
What kind of absolute maniac comes up with such a password policy? Demanding friggin' two numbers and then limiting the password length to ridculous 15 characters?
So I restrict my password manager to use what I consider to be a widely accepted subset of the printable characters, and then some random website will complain about the lack of this or that character. :(
It matters, because it is annoying. Password security rules should achieve two goals:
1. Actually improve security
2. Make it easy for users to choose a good password
A password policy of "chose one or more lowercase, one or more uppercase, two or more numeric and at least one special character, but not the one that you have been thinking of" does not achieve that goal, especially if they limit the password length to 15 characters.
Just tell give them a reasonable minimum length, check against the most common passwords and their username and call it a day. If you need more security, increase the minimum length.
Maximum length should be chosen in a way that nobody who is not malicious will notice it (e.g. 128 chars or bigger).
This produces safe passwords, is understandable and people with password managers are served as well.