Edit: Australia seems to be using the US system: http://www.bitdefender.com/security/hacking-virgin-mobile-us...
Edit: Australia seems to be using the US system: http://www.bitdefender.com/security/hacking-virgin-mobile-us...
In no particular order my usual gripes with passwords and auth in general are:
* Disabling clipboard copy/paste (because now I can't use my password manager)
* Length limitations (anything less than 32 characters is a a limitation)
* Requiring punctuation or "special characters" (they're annoying and don't add real security ... just use a longer password)
* Lack of two-factor (preferably TOTP)
The password limit is really the scariest one. Short passwords are much easier to crack. Also, I have a sinking feeling that every site that says a password must be a specific max length is storing it in plaintext. Otherwise why the heck would it matter what the length is? 10 char alphanum: 62^10, or 8.4e17
10 char alnumsym: 94^10, or 5.4e19
11 char alphanum: 62^11, or 5.2e19
One extra character instead of needing to type symbols into my phone, with nearly identical complexity? Sounds good to me.Your Account PIN must be:
-6 numbers (no letters or special characters)
-no more than 3 identical numbers in a row (222)
-no more than 3 sequential numbers (such as 234)
If I did the math right, that's approximately 900,000 possible passwords, which is obviously really low
I am curious what simple pattern people will adapt to once you eliminate simple sequences. It has got to be predictable, as in someone could put math behind it.
I'm of the opinion that everybody should be given public and private key at birth.
edit: On second look, that's exactly what you did in your example.