#PasswordFail

2025-06-18

Bonus #Joke:
Questionfor: What’s the difference between a good password and a bad joke?
Answer: A good password is hard to crack.

(It's #HootinTootinTuesday again! Post some jokes or funny memes under this hashtag today, and bring lots of smiles to #Mastodon.)

#Humor #Humour #FunnyMeme #Tech #2FA #Password #ITSecurity #PasswordFail #Anniversary #Marriage #MarriedLife

Two-panel comic. Top panel is a man staring at his laptop. It is daylight outside. He yells, "Honey, what's the password?"

From another room, she replies, "Our anniversary date."

In the bottom panel, it it nighttime. He is frowning and frustrated. He thinks to himself, "She did this on purpose."

Comic Credit:
"off the mark.com"
by Mark Parisi
MarkParisi@aol.com
2012 Mark Parisi Dist. by Universal UClick for UFS
2025-06-06

Was kann da schon schiefgehen?

@dumbpasswordrules
#passwordfail

Screenshot eines Teils einer Webseite, auf der ein Account erstellt werden kann. Folgender Text ist zu lesen:

In den folgenden Feldern bestimmen oder ändern Sie Ihr Passwort.
Zur Bestätigung wiederholen Sie bitte Ihre Eingabe.
Bitte kein < als Sonderzeichen verwenden!

Dann folgen zwei Eingabefelder fuer Passworte.

Ach wie schön dass niemand weiß, dass ich Passwörter in meine Passwort.txt schmeiß :thisIsFine: #passwordfail

2024-07-16

@hexaheximal 72 is a number I haven't seen... 32, 20, 40, 60, 50 have all been there - with 20 being PayPal, see social.tchncs.de/@jesterchen/1

I've had a huge collection of these sites at Twitter while I changed my 800+ passwords after LastPass.......

For more password fails search for #passwordfail or have a look at @dumbpasswordrules

2024-06-24

Waru, Conrad, warum?

#passwordfail

Screenshot einer Webseite:

Konto erstellen

Auswahl Privatkunde oder Geschäftskunde
Eingabefeld Email

Eingabefeld Passwort - gefüllt mit vielen  versteckten Zeichen
Fehlermeldung: Die Passwortlänge ist größer als die maximal erlaubte Länge 60 Zeichen
Ell 🏳️‍⚧️c9a@cathode.church
2024-03-01

Another #PasswordFail with some nice layers from Arrow Electronics. Right off the bat, we've got a max password length (boo!) and a "acceptable special characters" list (boo!!!), but the thing that spurred me to actually contact support was that the special character list wasn't taken into account in the individual validation bullets, so my password passed all the "checks" but still "didn't meet the requirements" 🙄​

Bonus absurdity: take a close look at that acceptable "special" character list. What the heck is going on there?? We've got:
- 0 and l (that's zero and lower-case L, which are...not special characters??)
- TWO zeroes and TWO periods
- Several spaces (do they count?)
- Absence of the most basic number-key special symbols, including !, &, and ()

But wait! There's more! In testing, it actually accepted a password with ! in it (but not spaces), so I dug in and present you the _actual_ list, which is totally different from the acceptable list:

a = /[~!@#$%^&*()\-_=+[\]{}|;:,.<>\/?]/g.test(this.$password) ? 'valid' : 'invalid'

A small mercy: there are no characters listed that aren't actually accepted.

But please, STOP CREATING ARBITRARY ACCEPTABLE SYMBOL LISTS!! There is zero technical reason for it, you should be hashing your passwords as soon as you get them anyway! Stop it!!! #PasswordFailHallOfFame

A screenshot of a password entry form with the "New Password" and "Confirm Password" boxes filled in, with an error on the first box saying "Password doesn't meet the requirements".

Below the fields is a list of items, all with green checks beside them, as follows:
- Between 12-25 characters
- At least one number
- At least one uppercase letter
- At least one lowercase letter
- At least one special character. Accepted special characters are ~@#$%^*0-_=+0l;..<>/?
2024-02-02

Ach, #ITSA, warum?

#passwordfail

Passworteingabefeld bei Registrierung eines Accounts, Fehlermeldung in rot: "Passwort muss mindestens 8 und maximal 40 Zeichen enthalten."
2023-12-06

Why, #Sophos, just why?

(Again: this is a serious question. Why is the length limited on the upper end?)
(Ok, and why only at 8 chars at the lower end?)

#passwordfail

Create Sophos ID

Your password should have at least 8 characters, uppercase and lowercase characters and numbers or special characters
The password must be between 8 and 50 characters.
2023-11-30

#passwordfail 8 characters? Seriously, @HubSpot

Create your password Password

- At least 8 characters
- One lowercase character
- One uppercase character
- One number, symbol or whitespace character
2023-11-27

#passwordfail
Warum? Waaarum?

Fehlermeldung: Passwort darf nicht länger als 20 Zeichen sein
2023-09-24

Nein, #Decathlon. Einfach nur nein.

Oder nennt mir einen validen technischen Grund dafuer.

#passwordfail

Das eingegebene Passwort ist zu lang, bitte verkürze es auf 48 Zeichen 

1 Großbuchstabe
1 Ziffer
1 Kleinbuchstabe
8 Zeichen
Kein Leerzeichen
Neil Carpenter :unverified:neilcar@infosec.exchange
2023-09-23

@tinker One of the last major incidents that I worked on happened because, when a user in the org called helpdesk for a password reset, the helpdesk set the password to season+year (Spring2023, Summer2023, etc) and did not tick "User must change password on next logon". The attackers (we attributed it to an Iranian group) were able to get to >100 users who had never changed their password after a reset.

#PasswordFail #IncidentResponse #NationalCyberSecurityAwarenessMonth

Natouille 🍷 🥃 🍾Natouille@mastodon.tetaneutral.net
2023-08-07

Et encore un #PasswordFail

"Vous pouvez choisir le mot de passe qui vous est suggéré ou en saisir un de votre choix. Il doit compter entre 8 et 20 caractères dont au moins une majuscule, une minuscule et un caractère spécial parmi : @ $ € ! * ? _ , . . ; § / - +."

2023-07-31

One of my tools just greeted me with:

"Your password has expired or no longer complies with the security policies. Please enter a new password!"

How the **** do they know, my password might no longer comply with security policies? Do they store meta information about my password or - which is even worse - the plaintext password?

Or do you have any other idea, how a test like this might be accomplished?

#passwordfail

2023-01-13

#SquareEnix, your password and e-mail restrictions, use of security questions and other sign-up form requirements suck...

  • Password field can't be pasted into
  • Password field can't be filled by the browser's password generator (option doesn't show up)
  • Password phrases aren't possible as spaces seem to be disallowed
  • Additional restrictions such as limiting the amount of repeated characters only provide additional rules for brute force systems, thus reducing the total amount of possible choices. In addition they make it hard for password generators to create a valid password.
  • Putting limitations on the kinds of special characters allowed, makes me wonder doubt your user input sanitation...

In addition to this, they are asking for a 'security question', which are notoriously easy to find, guess or social engineer.
The first couple of answers I gave were also refused.

Plus-signs are also not allowed in the e-mail address field, thus making it impossible to use #PlusFiltering, while also going against the #EMailRFC, which states that plus signs are allowed in the local-part of the address.

#Password #Passwords #PasswordFail #Security #SecurityFail #Squeenix #SquareEnix #FFXIV #emailFail #PasswordRestrictions #SecurityQuestions

"Alphanumeric characters and the following symbols can be used for your password:
!"(#$%&')=~\`{+*}<>?_-^@[;:],./
Please enter a password within 6 to 32 alphanumeric characters.
You cannot use the following as passwords:
- Any password made up of only letters,only numbers or only symbols.
- The same text as your Square Enix ID.
- The same text as the characters before your e-mail address's @ sign.
- Any text string with the same character repeated 3 times.""Please enter a valid e-mail address."
exampleaddress+squeenix@gmail.com
2022-12-19

Oh, web​.de..... warum nur? Nicht einmal die Zeichensetzung ist korrekt...

#passwordfail

Screenshot von web.de mit folgender Fehlermeldung zum neugewaehlten Passwort: "Bitte entfernen Sie mindestens 24 Zeichen. (Die maximale Länge beträgt 40)."
Yuki the Mavenyuki_the_maven
2017-04-05

you leave the machine on for so long that you forget part of the disk encryption password
that exponential backoff was starting to look hella scary >___<

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst