#passwords

2026-02-14

This dumb password rule is from Dutch Tax Authorities (Belastingdienst).

At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password.
No more than 3 of the same characters.
At least 1 upper case and 4 lower case characters.
No more than 3 special characters.

It's not like hashing passwords is a thing or something.

dumbpasswordrules.com/sites/du

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-13

This dumb password rule is from UniSuper.

Passwords need:
- a lower case letter
- a number
- a capital letter
- at least 8 characters

In the 'Change password' form,
passwords are now restricted to a `maxlength` of 18.

If your current password is longer than 18 characters,
you won't be able to change your password.
When I contacted them...

dumbpasswordrules.com/sites/un

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-13

This dumb password rule is from Three.

Password must be at least 7 characters long.
The maximum length is inconsistent, however: when changing password, the maximum length is 30, but when resetting password via email link, the maximum length is 12.

dumbpasswordrules.com/sites/th

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-12

Stop memorizing your passwords. Seriously.

Your brain is designed for patterns, not encryption. If you can remember your password, it is weak.

In the next video, we are fixing your digital hygiene. No closed source "just trust me, bro" apps. No browser saving. FOSS digital sovereignty.

Which side are you on right now?

#Bitwarden #Vaultwarden #Proton #ProtonPass #KeePassXC #Firefox #Chrome #Edge #Safari #Passwords #Password #Cybersecurity #Security #Privacy #FOSS #OpenSource #GNULinux #GNU #Linux #NoAI #DigitalSovereignty

2026-02-12

This dumb password rule is from University of Texas at Austin.

Because of the last two rules, which ban dictionary words and any
variants using symbol substitutions, *neither* of the passwords
presented in the [xkcd comic](xkcd.com/936/) are allowed.

dumbpasswordrules.com/sites/un

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-12

This dumb password rule is from Dwr Cymru (Welsh Water).

Limits password length to a maximum of 16 characters

dumbpasswordrules.com/sites/dw

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-12

Your Friendly Reminder

to change/update your passwords!

Perhaps the last time you did so was back in the early ‘00s when 10 characters was considered ‘safe.’ 😝

Time to kick it up a notch. 😅

👋🐙

#infosec
#passwords
#CyberSecurity

2026-02-11

🚨 Episode 13 “Password Panic” just dropped.

What’s the first lock you’ll reinforce on your digital front door?

Tune in for the why and the how: impracticalprivacy.com

2026-02-11

This dumb password rule is from Air France.

- Between 8 to 12 characters
- Should contain capital, lowercase letters and numbers

dumbpasswordrules.com/sites/ai

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-11

This dumb password rule is from Interactive Brokers.

Usual dumb password restrictions, but this one has incredibly dumb **username**
restrictions too:

**Username:**
- **Length of 8 or 9 letters and numbers**
- **Contain at least 3 letters and 3 numbers**
- Begin with a letter
- Lower case only, no spaces, no special characters

**Password:**
- Can...

dumbpasswordrules.com/sites/in

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Pickrpickr
2026-02-10

AI is a part of life for many people, but it's also something scammers are using. How do you stay safe in a world where AI is present? pickr.com.au/how-to/2026/how-t

2026-02-10

Storm-2603 Exploits CVE-2026-23760 to Stage Warlock Ransomware

A critical vulnerability in SmarterMail email server software (CVE-2026-23760) is being actively exploited by the China-based threat actor Storm-2603. The group uses this vulnerability to bypass authentication, reset administrator passwords, and gain full system control through the software's 'Volume Mount' feature. They then install Velociraptor, a legitimate digital forensics tool, to maintain access and prepare for deploying their Warlock ransomware. The attack chain involves exploiting the password reset API, abusing administrative features, and using legitimate tools to blend in with normal activity. This sophisticated approach allows the group to bypass detection mechanisms and establish persistence. The report also notes simultaneous exploitation attempts of another vulnerability (CVE-2026-24423) against the same targets, highlighting the urgent need for patching and improved security measures.

Pulse ID: 698b63d4a7a0ee426b30664d
Pulse Link: otx.alienvault.com/pulse/698b6
Pulse Author: AlienVault
Created: 2026-02-10 16:59:00

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#China #CyberSecurity #ESET #Email #ICS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RAT #RansomWare #SMS #Vulnerability #Word #bot #AlienVault

2026-02-10

Password Security in 2026: A Practitioner’s View

After years in security, I can say one thing with confidence: most breaches still don’t start with zero-days. They start with credentials.

Phishing, credential stuffing, password reuse — same story, different year.

From the offensive side, weak or reused passwords are still one of the cheapest ways in. From the defensive side, identity remains the most fragile layer in otherwise decent infrastructures.

What I keep seeing in real environments:

The same password reused across multiple services

“Seasonal” patterns like Summer2026!

Credentials leaked in one breach and reused elsewhere

Missing MFA on systems that really should have it

This is why the basics still matter more than shiny tools:

Use a password manager and generate long, random, unique passwords

Use passphrases for master credentials

Enable MFA / 2FA everywhere it’s possible

Treat access reviews and account cleanup as a routine, not an incident response

Technology alone won’t save you, though. If policies are unclear or not enforced, people will always take shortcuts. And shortcuts in identity and access management are exactly what attackers love.

In 2026, this is not about “making life harder for users”. It’s about:

Reducing breach probability

Limiting blast radius

Protecting business continuity

And not turning basic hygiene into an expensive incident

Strong authentication is no longer “advanced security”. It’s just digital hygiene.
And like any hygiene, it only works if it’s systematic and boringly consistent.

#infosec #cybersecurity #passwords #identity #MFA #2FA #bluesky #mastodon #securityengineering #digitalhygiene

2026-02-10

This dumb password rule is from Minecraft.

Using a 16 character password seems to work. Everything else above does not always work.
Also, passwords that are too long are still changed, so you have to reset them by email.

dumbpasswordrules.com/sites/mi

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Absolute Memery 🎭AbsoluteMemery@tribe.net
2026-02-10

MyAbilityToEmbarrassMyself - Very Strong
#Password #Passwords #InfoSec #Security.

#Meme #Memes #Humour #Humor

2026-02-10

This dumb password rule is from South Western Railway.

Certain special characters disallowed, but notably the phrase " or " is disallowed also. They're probably papering over SQL injection vulnerabilities 🤦

dumbpasswordrules.com/sites/so

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-09

@cstross @cR0w

The question in everyone's lips now has to be:

Is 'hippo, fart, milk battle, crème brûlée harvest capybara raccoon cows' a more secure password than #CorrectHorseBatteryStaple ?

#infosec #passwords

2026-02-09

This dumb password rule is from Coil.

Does not allow simple characters and sequences such as '4587' or 'efgh' in password & necessarily requires numeric values.

dumbpasswordrules.com/sites/co

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst