/dumb-password-rules

Shaming sites with dumb password rules.

Dumb Password Rules

Shaming sites with dumb password rules.

Contributing

Feel free to submit a pull request with dumb rules you've encountered.

See other sites for the formatting and follow these rules:

  • Include the name of the site with a link.
  • Add a clean comment about the dumb password rule (optional).
  • Include at least one screenshot.
  • Keep the sites in alphabetical order.

Sites

Sometimes I forget that caps-lock is on, glad it doesn't matter.

American Express

Their site says "All information is kept safe and secure." Just not as secure as you'd like.

User Password must be between 6 and 14 characters and contain 1 numerical value.

AmeriHealth

Your password contains characters not listed. Therefore, they do not match.

Arlo

You can enter whatever password you like! But you probably don't want to make it too long, because you'll break us and you'll never be able to login again.

Best Buy Best Buy

The auto-generated strong password is not a valid password ! Blacknight use Odin for it's admin panel.

Blacknight Blacknight

16 maximum and no special characters. Protecting your US healthcare information.

Blue Cross Blue Shield Massachusetts

Password must be exactly 6 characters long and no special character.

BMO Bank of Montreal

We don't even want you to login online.

Chase Bank

Your password should be difficult to guess as long as it's not over 16 characters long.

Comcast

No more than 20 characters and leave out characters commonly used by programmers. We don't want you to hack the mainframe.

Fidelity

You "may use special characters", but only some of them - and we won't necessarily tell you which ones.

Mindware Mindware

We'll tell you not to use your name as your password, but we won't tell you how we restrict your password choice otherwise.

PayPal

/\d{6}/

Singapore Airlines

Financial services - where we don't allow you to create the strongest password possible.

Synchrony Financial

Pick from an arbitrary list of symbols, and no repeating characters.

United States Postal Service

Your password needs to be between 8 and 10 characters long, with no spaces, and must contain only numbers and letters. The first character must be a letter.

Virgin Media

We put punctuation in the list of unusable characters to make it additionally confusing.

Williams-Sonoma