• Landless2029@lemmy.world
    link
    fedilink
    arrow-up
    62
    arrow-down
    2
    ·
    11 days ago

    Never have this problem anymore with a password keeper. All new passwords are unique.

    What REALLY pisses me off is when:

    • register for account
    • cannot register, account already exists
    • password reset
    • account not found
    • Serinus@lemmy.world
      link
      fedilink
      arrow-up
      29
      ·
      edit-2
      11 days ago

      I absolutely do. It’s not that the password was wrong. It’s that they wanted to invalidate all existing passwords and make you change it.

      The easiest way to do that is for them to force everyone through the “forgot password” workflow. Zero or minimal code changes. They don’t want to make a new, but very similar , “we had a security breach and are requiring you to change your password” workflow. They just don’t care that they’re blaming you for their problem.

    • Vanilla_PuddinFudge@infosec.pub
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      11 days ago

      We require our users use a password that is in between 8 and 14 characters, contains more than 2, but not exceeding 4 special characters, and at least 3 uppercase letters, 3 numbers with 0 repeating digits.

      Generator: “…fuck you?”