search
Dumb Password Rules
Trends
- 1Commsec criticised over short password rules and paste blocking▼This dumb password rule is from Commsec. Another financial institution with short password requirements. They also block
Commonwealth Securities (Commsec) is facing criticism from security-conscious users for capping password length and blocking pasting into its login field, which makes password managers difficult to use. Commenters say short password limits and anti-paste rules are outdated practices that push customers toward weaker, reused passwords, and they are calling on the brokerage to modernise its authentication requirements.
- 2Mindware mocked for confusing password character rules●This dumb password rule is from Mindware. You "*may use special characters*", but only some of them - and we won't neces
Security enthusiasts are calling out Mindware over its password requirements, which reportedly allow special characters but only a select, unspecified subset of them. The complaint, circulating in cybersecurity circles, argues that failing to tell users which symbols are permitted makes it needlessly hard to create valid, secure passwords, turning a basic usability issue into a running example of poorly designed password policies.
- 3ADP criticized for clumsy forced password change rule▼This dumb password rule is from ADP. Forced to change the password during the first login. At least they could use prope
ADP, the US payroll and HR services giant, is being mocked online for its first-login password policy, which forces new users to change their password immediately. Critics say the enforcement message is poorly written and the rule itself adds friction without improving security. The complaint has been logged on a site that catalogues bad password requirements at major companies, drawing agreement from security professionals who argue such forced resets often push users toward weaker, predictable passwords.
- 4WeatherBug mocked for 16-character password limit●This dumb password rule is from WeatherBug. Maximum 16 characters. https:// dumbpasswordrules.com/sites/we atherbug/ # p
WeatherBug is being criticised for capping account passwords at 16 characters, a restriction catalogued on a site that collects poor password policies. Security-minded users point out that short maximum lengths discourage long passphrases and can signal outdated or unsafe password handling behind the scenes.
- 5Mortgage servicer Rushmore criticised for password rules blocking quotes▼This dumb password rule is from Rushmore Loan Management Services. Hmmm.. why are they afraid of double and single quote
Security-conscious users are mocking Rushmore Loan Management Services for a password policy that rejects single and double quote characters. Poorly designed password restrictions are a recurring target of ridicule among information security professionals, who argue arbitrary character bans suggest bad handling of user input and weaker overall security practices.
- 6MetLife mocked over restrictive password rules●This dumb password rule is from MetLife. Max length of 20 characters, no special characters allowed. Pasting into the se
MetLife is being criticised online for requiring account passwords of no more than 20 characters, banning special characters, and blocking pasting into its password confirmation field. Security commentators say such rules push users toward weaker passwords and discourage password managers, running contrary to widely accepted guidance from standards bodies like NIST.