-
-
Notifications
You must be signed in to change notification settings - Fork 302
Description
I am thankful that so many people have been willing to create this list.
Thank you!
We now have an ever-growing list of those that have it wrong.
And it appears from this list that most sites have it wrong.
Here's a challenge:
Tell us your preferred password policy that:
- balances usability with security, and
- supports popular password managers and generators, and
- will work at least on popular desktop and mobile browsers and in mobile apps.
Not kidding! Come up with a "good" password policy - so at least when one of these sites fixes their password policy, you can kindly and unarguably remove them from the shame list.
You will be doing the world a great service! Then at least if everyone adopts your policy, everyone will have better passwords, and people can use passwords that follow a pattern even though not the same since everyone reading this knows you SHOULD (RFC 2119) use a different password everywhere.
Once you come up with that, comb through your list again and see if any site is already compliant.
Thank you - sincerely - thank you!