Context is that I had to register for a lot of accounts recently and some of the rules really make no sense.
Not name-and-shaming, but the best one I’ve seen recently is I might have accidentally performed an XSS attack on a career portal using a 40-digit randomly generated password…
My old bank required you to have a password 12 characters long exactly, and to login you have to give the characters in specific places.
I would ask you what are the 4th, 7th, and 11th letters of your password.
Anyone want to guess why that aren’t my bank anymore?
Oh yeah, mine has that as one of the options, but they’ve beefed it up a little. You also have to enter your date of birth and then they send a text to a pre-arranged number with a further 6-digit PIN that also has to be used.
E and U and 2