#dumbpasswordrules

2026-02-06

This dumb password rule is from Easybank (Austrian direct bank).

- At least 8 and at most 16 (!) characters
- **Must start with 5 digits (do we really want to know what's going on there?)**
- At least one uppercase and one lowercase letter
- (Some) special characters are permitted, most are not
- "Simple" patterns are prohibited
- PINs are case sensitive (at l...

dumbpasswordrules.com/sites/ea

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-05

This dumb password rule is from Tanishq.

Password must contain:
- 6 to 16 characters.
- At least one special character (@, #, $, %, * and & only).
- At least one alphabet.
- At least one number.

dumbpasswordrules.com/sites/ta

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-05

This dumb password rule is from Virgin Media.

Your password needs to be between 8 and 10 characters long, with no
spaces, and must contain only numbers and letters. The first character
must be a letter.

Feb 2020 Update: policy remains the same but the description is hidden
leaving you to guess the acceptable length/chars. Users are now lef...

dumbpasswordrules.com/sites/vi

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-04

This dumb password rule is from Parnassus Investments.

A site responsible for protecting your investments limiting you to a
four character range with a bunch of other stupid rules? Shocking.

dumbpasswordrules.com/sites/pa

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-04

This dumb password rule is from Datart.cz.

Czech eshop

Password:
- Max length is 20 characters
- No special characters allowed (only alphanumeric)

dumbpasswordrules.com/sites/da

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-03

This dumb password rule is from A1 Mobile Serbia.

A1 mobile Serbia is a mobile provider in Serbia that imposes poor password rules.

Translation: "Length of the password must be between 8 and 20 characters and can only have letters and digits."

dumbpasswordrules.com/sites/a1

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-03

This dumb password rule is from ING Romania's Internet Banking Portal.

No more, no less than 5 digits. This is the password you use to log in and to confirm
online transactions. They used to have "normal" passwords and they forced everybody to
change to the 5 digits versions. They said they've made it "so it's easier for you" and it's
OK, because everybody has 2FA.

dumbpasswordrules.com/sites/in

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-02

This dumb password rule is from Techcombank.

Your password must:
- Be between 6 and 8 characters long
- Contains at least 1 number character
- Contains at least 1 lowercase character
- Contains at least 1 uppercase character
- Neither space nor unicode character is allowed. In fact,
NO special characters is allowed
- Must be changed every 9...

dumbpasswordrules.com/sites/te

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-02

This dumb password rule is from Polytechnique Montreal.

Passwords must have a minimum length of 8 characters

Passwords must have a maximum length of 30 characters

Passwords must contain a minimum of 2 digits

Passwords must contain a minimum of 2 letters

Password must be different than the last one used

Passwords may contain these special characte...

dumbpasswordrules.com/sites/po

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-01

This dumb password rule is from Credit Agricole.

* Login is a predefined 11 digits long identifier that you can not change
* Password is a 6 digits long identifier that you need to input using your mouse

dumbpasswordrules.com/sites/cr

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-02-01

This dumb password rule is from Anthem.com.

* Use 8-20 characters.
* Use 1 letter and 1 number.
* $ ! @ * ? | also allowed.
* Don't use spaces.
* Don't use the same character three times in a row.
* Don't use part of the username.

dumbpasswordrules.com/sites/an

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-31

This dumb password rule is from NordVPN.

- Password cannot be longer than 48 characters.

dumbpasswordrules.com/sites/no

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-31

This dumb password rule is from CAF (French Family Allowance Fund).

You have to enter your 8-digit password using this Frenchy keypad.

dumbpasswordrules.com/sites/ca

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-30

This dumb password rule is from College Board.

Password must be 9-30 characters with at least one upper case letter, one lower case letter, one number and one special character (no spaces) and be different than your username.

dumbpasswordrules.com/sites/co

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-30

This dumb password rule is from CENLAR.

Your password can meet all the requirements in the list and still be invalid due to
an unspecified rule: any "special characters" that are not listed in the help text
are not allowed. Worse, it provides no useful feedback other than the "New Password"
field is red.

dumbpasswordrules.com/sites/ce

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-29

This dumb password rule is from NVV (Nordhessische VerkehrsVerbund).

Password length must be 4 to 10 characters with only a few special characters allowed.

dumbpasswordrules.com/sites/nv

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-29

This dumb password rule is from PayPal.

Must be between 8 and 20 characters, no spaces, uppercase and lowercase, one symbol...

The rule limits special characters to !@#$%^&*(). but my current password has a "-" in it so someone decided to restrict this further which is totally backwards. Things are meant to get better not worse!

dumbpasswordrules.com/sites/pa

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-28

This dumb password rule is from Tanishq.

Password must contain:
- 6 to 16 characters.
- At least one special character (@, #, $, %, * and & only).
- At least one alphabet.
- At least one number.

dumbpasswordrules.com/sites/ta

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-28

This dumb password rule is from Taleo.net.

Oracle Taleo is one of those old-school enterprise Applicant Tracking
Systems (ATS) that half the corporate world still uses even though
everyone hates it.

dumbpasswordrules.com/sites/ta

#password #passwords #infosec #cybersecurity #dumbpasswordrules

2026-01-27

This dumb password rule is from Bank of America.

20 character max and lots of special character restrictions.
Bank of America - keeping your money safe.

Also: If you paste a password greater than 20 characters,
the form truncates it without telling you or giving an
error.

dumbpasswordrules.com/sites/ba

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst