#passwordpolicy

LDAP Tool Box Projectltb_project@floss.social
2024-12-31

✨ LTB Service Desk 0.6.1 released!

📰 Some fixes needed after 0.6 release, mostly for AD compatibility and Docker images

🔗 projects.ow2.org/view/ldaptool

#LDAP #OpenLDAP #ActiveDirectory #Password #Security #PasswordPolicy

Screenshot of Service Desk 0.6
Rene Robichaudnerowild
2024-12-04
2024-07-22

Must not contain the characters <, > or spaces.
account.docusign.com

Do I get it correctly, that you disallow < and > symbols because you display plaintext passwords on HTML pages/other XML documents without proper encoding?

Do you use plaintext passwords for filenames (surely <, > and spaces are bad options for filenames)?

What could be the reasons to prohibit these symbols?

@docusign
@dumbpasswordrules
@duffn
#passwordpolicy

docusign
Finish signing up with a password
Password
Must be at least 6 characters long.
Must not contain the characters <, > or spaces.
2024-07-09

Ok found a blog post explaining it, from my reading it's equally good (or bad) as the Apple one.

So I'm going to put in the #passwordpolicy that synced passkeys are OK.

But I'd love for someone with real experience extracting/stealing these to tell me why I'm wrong about this and why it'll get us hacked.

d0rk ✅drwetter
2024-01-29

oh, well, even you

2023-12-05

Passwords generated by pass shall not pass.
MyAnimeList

  • Password must be between 6 - 50 characters long and contain at least two of the following: uppercase, lowercase, numbers and symbols.
  • Password may only contain letters, numbers and the following symbols: ! "#$%&'()*+,-./:;<=>?@[]_{|}~.

@MyAnimeList #passwordistoostrong #passwordpolicy @duffn

Kyle Rankinkyle@kylerank.in
2023-07-24

Online accounts forcing you to rotate passwords periodically is bad enough, but even worse is when you use a password manager, and they reject the first password you generate because it fails some arbitrary complexity requirements (with no warning before submission).

So now it wants my "old" password, but of course in my password manager that's been replaced with this new one, so I get to go through the password reset workflow instead...

#passwords #PasswordPolicy

2023-04-30

Do password meters discourage users from using complex passwords? Should password meters take into account the likelihood of a password being guessed by an attacker? Should I use a blacklist of commonly used passwords to prevent users from using weak passwords?

Get answers: jbspeakr.cc/password-strength-

#passwords #passwordpolicy #credentialstuffing

Troed Sångbergtroed@ioc.exchange
2023-02-06

Let's discuss in small groups - TP-Link's "Business Solution" TL-SG switches password policy.

No, no - not recommended. You're unable to set passwords longer than 16 characters, and the only special character besides the _English_ alphabet and numbers is ... underscore.

Let's list all the reasons we can think of. I'll start:

*) what's a hash?
*) [...] government told us to

#TPLink #PasswordPolicy #backdoor #crackable #infosec

TP-Link "Business Solution" switches, TL-SG series, enforces password policy 6-16 characters using _only_ English letters, digits and underlines.
Joseph Scottjosephscott
2023-01-03

Please do not do this with your

OPSEC Cybersecurity News LiveOpsecNews@aspiechattr.me
2022-12-23

Password restrictions limit Diceware word list - (when) can this get bad enough one should choose another strategy?

security.stackexchange.com/que

#passwordpolicy #passwords

Geekmaster 👽:system76:Geekmaster@ioc.exchange
2022-12-03

@Xavier oh, I see what you mean. This isn't against our #website, it's logins against #MicrosoftExchangeOnline via an #API trying to #hack into accounts. They're not even using great #passwords to spay with lol. We have #MFA enforced across the #enterprise, #PasswordPolicy is well designed, and #governance in play. I could put additional controls in place, sure, but we don't have a requirement too do so, and we feel satisfied about where we're at - good blending of security and usability.

Sebastian "spaetz" Spaethspaetz@mas.to
2022-09-22

Sorry for keeping going on but the webform finds this password: zZ?S*C>O?7dgY7 "Weak".
It also finds this one 8B2AI6 "Fair".

What have those webdevs smoked? #passwordpolicy

2020-04-13

Die erlaubten Zeichen bei Logins sind überall anders definiert, wieso kann man nicht alle Zeichen auf einer Tastur als Zeichen für die Passwortvergabe definieren. Mir erschließt sich die Problematik nicht. Es kann doch nicht sein das man im Jahr 2020 immer noch solche Restriktionen hat.
#Passwort #passwordpolicy

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst