Dumb Password Rules
I'm a bot posting random sites from https://dumbpasswordrules.com.
Created by @duffn@fosstodon.org.
Also posting on Blue Sky at https://bsky.app/profile/dumbpasswordrules.bsky.social.
This dumb password rule is from GoDaddy.
Some characters are too special.
https://dumbpasswordrules.com/sites/godaddy/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Hetzner.
- 8 or more characters
- At least one uppercase and one lowercase letter
- At least one number or special character
Okay, fair enough, but after putting in a password with some special characters this message appears:
- Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...
https://dumbpasswordrules.com/sites/hetzner/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Wageworks.
In addition to the following rules regarding passwords...
- 8-20 characters in length
- Include at least 4 of the following: lowercase letter, uppercase letter, number AND symbol
- Not include your last name, first name or space
Your new password should be different from your previous twenty pas...
https://dumbpasswordrules.com/sites/wageworks/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Pole-Emploi.
Password must contain at least one letter, one number and one character from &-_@*%=.,;:!? only.
It rejected passwords generated by pass, while accepting p@ssw0rd!...
They also block pasting on the password confirmation field,
forcing you to manually type your 32-letters-long generated passwo...
https://dumbpasswordrules.com/sites/pole-emploi/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Netflix.
The help page and the password reset page say:
Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.
https://dumbpasswordrules.com/sites/netflix/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Fidelity National Information Services.
White label online banking provider. Typically appears as BANK.ibanking-services.com or BANK.ebanking-services.com. If your small local bank has a crappy online banking experience, these guys probably provide it.
\<>' and spaces prohibited, upper bound. Passwords of exactly the maximum len...
https://dumbpasswordrules.com/sites/fidelity-national-information-services/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from State Bank of India (Foreign Travel Card).
State Bank of India is the largest government operated bank in India. They offer "travel" prepaid cards for foreign currencies, this is for their portal for the prepaid card users to manage their account.
Your password must:
- Be between 8 and 9 characters long
- Contain at least 1 lowercase c...
https://dumbpasswordrules.com/sites/state-bank-of-india-foreign-travel-card/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Netflix.
The help page and the password reset page say:
Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.
https://dumbpasswordrules.com/sites/netflix/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from BBVA.
Username is your national ID (easy to find) and your password must have up to 6 alphanumeric characters only. For a bank account with all your money in one of the largest financial institutions in the world.
https://dumbpasswordrules.com/sites/bbva/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Targobank.
Your password must:
- must not be your username
- must at least eight characters
- must contain at least one number character
- must contain at least one uppercase character and 1 lowercase character
- must not contain spaces
- must not contain three identical characters in a row
- must not conta...
https://dumbpasswordrules.com/sites/targobank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from SONY.
- between 8 and 30 characters
- at least one number or special character
- not part of email address
- avoid common passwords
- repeating characters 3 or more times should be avoided
- currency characters and 3 or more consecutive characters, also in reverse order, should be avoided Somehow "$" i...
https://dumbpasswordrules.com/sites/sony/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from E-Trade.
Causes:
- Your two-factor authentication code must be appended to the end of the password
- Passwords have a limit of 32 characters
Effect:
If your account has a 32-character password and has two-factor authentication, their system appears to cut off the token, making it impossible to login. Yo...
https://dumbpasswordrules.com/sites/e-trade/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Really Useful Storage Boxes.
- Have a length between 8 and 20 alphanumeric characters (without accents)
- Contain at least 1 CAPITAL letter
- Contain at least 1 lowercase letter
- Contain at least 1 numeric character
- Contain at least 1 special character taken from the following list: *$@&()[]{}=#.-!?+/£€%
https://dumbpasswordrules.com/sites/really-useful-storage-boxes/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Sharekhan.
- At least 8 characters.
- At most 12 characters.
https://dumbpasswordrules.com/sites/sharekhan/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from AOK (German Health Insurance).
This is the online customer portal of the German health insurance company AOK. They have an extensive set of rules for both passwords and usernames.
The password rules are:
- Length between 8 and 14 characters
- At least one letter, one number and one special character
- Special characters are: !...
https://dumbpasswordrules.com/sites/aok-german-health-insurance/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from University of Western Australia (Pheme).
Passwords:
- Must contain at least 8 characters;
- Must contain at least 3 out of 4 types of characters (uppercase letters, lowercase letters, digits, special characters); and
- Must not contain "the user's account name or parts of the user's full name that exceed two consecutive characters". ...
https://dumbpasswordrules.com/sites/university-of-western-australia-pheme/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Air France.
- Between 8 to 12 characters
- Should contain capital, lowercase letters and numbers
https://dumbpasswordrules.com/sites/air-france/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from KPMG Talent Community.
While stating otherwise, the site actually accepts a backslash in the password and displays a forward slash as the example of the disallowed backslash Password:
- Must be at least 8 characters long
- Must contain at least 1 number
- Must contain at least 1 letter
- Must contain at least 1 spec...
https://dumbpasswordrules.com/sites/kpmg-talent-community/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Rediff.
A maximum password length of 12. The hidden requirements are:
- at least 1 uppercase letter
- at least 1 lowercase letter
- at least 1 numeric character
- at least 1 special symbol (which can not be ^, %)
https://dumbpasswordrules.com/sites/rediff/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from University of Texas at Austin.
Because of the last two rules, which ban dictionary words and any variants using symbol substitutions, neither of the passwords presented in the xkcd comic are allowed.
https://dumbpasswordrules.com/sites/university-of-texas-at-austin/
#password #passwords #infosec #cybersecurity #dumbpasswordrules

















