#dumbpasswordrules

2025-06-19

This dumb password rule is from Suncorp.

To "improve security" and "be password savvy", passwords must:
- be six to eight characters long
- Contain both numbers and letters
- Include upper and lowercase letters

dumbpasswordrules.com/sites/su

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-19

This dumb password rule is from Onleihe.

Password is your birthday in format ddmmyyyy. Users are not allowed to change their passwords

dumbpasswordrules.com/sites/on

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-18

This dumb password rule is from California Department of Motor Vehicles.

They also prohibit pasting into the password field by using a JavaScript
`alert()` whenever you right-click or press the `Ctrl` button, so
you can't use a password manager.

dumbpasswordrules.com/sites/ca

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-18

This dumb password rule is from Mycanal.

- Minimum of 8 characters
- Contain at least 1 uppercase character or 1 number
- Can not contain these characters : ‹ › ' "

dumbpasswordrules.com/sites/my

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-17

This dumb password rule is from Wageworks.

In addition to the following rules regarding passwords...
- 8-20 characters in length
- Include at least 4 of the following: lowercase letter, uppercase letter, number AND symbol
- Not include your last name, first name or space

Your new password should be different from your previous twenty pas...

dumbpasswordrules.com/sites/wa

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-17

This dumb password rule is from Dell.

Okay at least 6, that's alright I guess.

Oh at least one number and one letter, bit dumb but hey not that dumb.

But hiding the fact that it has a max of 20, now THAT is dumb!

dumbpasswordrules.com/sites/de

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-16

This dumb password rule is from Netflix.

[The help page](help.netflix.com/de/node/54078)
and the [password reset page](netflix.com/password) say:

Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.

dumbpasswordrules.com/sites/ne

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-16

This dumb password rule is from Ameli.fr (French national health insurance).

This was very painful to find a password that works with this one and that I can actually remember (I ended-up using my bank-account number because everything else failed). It took me maybe one hour and I thought I would become crazy (and yes, the session expires frequently while you are actually...

dumbpasswordrules.com/sites/am

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-15

This dumb password rule is from El Corte Ingles.

Min 6 and max 8 characters for password! Can't contain anything
different than letters and numbers. Apart, the email address must have
at least 8 characters (sorry million dollar domain owners! :D)

dumbpasswordrules.com/sites/el

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-15

This dumb password rule is from University of California San Diego.

Passwords must be between 8 and **11** characters long!

dumbpasswordrules.com/sites/un

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-14

This dumb password rule is from Getin Bank.

The new password should contain at least 10 and a maximum of 20 characters.
The password must contain at least one upper case letter, one lower case
letter and one number. The password cannot contain non-ASCII Polish alphabet
characters, special characters `&<'"` or spaces.

dumbpasswordrules.com/sites/ge

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-14

This dumb password rule is from Chase Bank.

* Can't use any special characters except ! # $ % + / = @ ~
* Max length restriction (32 characters).
* No runs of identical characters ("aaa") or sequential characters ("abc").
* Password check is case-insensitive

dumbpasswordrules.com/sites/ch

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-13

This dumb password rule is from PayPal.

Must be between 8 and 20 characters, no spaces, uppercase and lowercase, one symbol...

The rule limits special characters to !@#$%^&*(). but my current password has a "-" in it so someone decided to restrict this further which is totally backwards. Things are meant to get better not worse!

dumbpasswordrules.com/sites/pa

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-13

This dumb password rule is from Westpac Live Online Banking.

Password rules:
- be between 8 and 30 characters
- include at least 1 number, 1 letter and 1 special character (@#%^ etc)
- have no more than 2 repeating characters (AAB not AAA)
- not contain spaces
- not be the same as your last 3 passwords

dumbpasswordrules.com/sites/we

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-12

This dumb password rule is from Bank Leumi (Israel).

- Password consists of 6 to 12 characters
- Password contains only english letters and numbers without spaces.

dumbpasswordrules.com/sites/ba

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-12

This dumb password rule is from Taco Bell.

Password may include special characters, except for #.

dumbpasswordrules.com/sites/ta

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-11

This dumb password rule is from Nintendo.

Password between 8-20 characters, at least two "categories" of characters, and cannot use the same character more than twice in a row. At least it supports MFA.

dumbpasswordrules.com/sites/ni

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-11
2025-06-10

This dumb password rule is from Banque de Tahiti.

You have to enter your password using this *very* Frenchy keypad. You don't have lowercase letters, the blanks are not spaces but just non-clickable gaps, but as a compensation you have some weird symbols that your keyboard does not have a key for (e.g. `µ`).

No accessible version available.

dumbpasswordrules.com/sites/ba

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2025-06-10

This dumb password rule is from EON.

By the time I'd finished reading the rules I've forgotten all of them.

dumbpasswordrules.com/sites/eo

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst