Friday, August 30, 2013

American Express

American Express, your password policies are shitty.


  • Limited to 20 characters.
  • No spaces
  • Only allow "%,&, _, ?, #, =, -" as "special characters"
  • NOT CASE SENSITIVE? ARE YOU FUCKING SERIOUS?
  • Seriously.  Not being case sensitive is really fucking awesomely retarded.
I think the "not case sensitive" thing deserves a tad of discussion. Not having case sensitive makes it MUCH EASIER for someone to guess passwords, because they automatically know that caps dont matter.  That can as much as half the bits of entropy.  It eliminates the extra bits you'd get for having a number and/or one of the 7 special characters they "allow" you to have.

No comments:

Post a Comment