banner
dumbpasswordrules.bsky.social
@dumbpasswordrules.bsky.social
This dumb password rule is from Tangerine.

Your PIN can only contain numbers and must be between 4 and 6 numbers.

https://dumbpasswordrules.com/sites/tangerine/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
Tangerine - Dumb Password Rules
Your PIN can only contain numbers and must be between 4 and 6 numbers.
dumbpasswordrules.com
November 15, 2025 at 3:00 AM
This dumb password rule is from Canva.

Does not show number of characters in the max character limit.

https://dumbpasswordrules.com/sites/canva/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
Canva - Dumb Password Rules
Does not show number of characters in the max character limit.
dumbpasswordrules.com
November 14, 2025 at 2:42 PM
This dumb password rule is from Lloyds Bank.

Max 15 characters, min 8. You cannot use **ANY** special characters -
alpha-numerics only. This amazingly terrible password policy combines
with a known phrase (The "Memorable Information") of which you will be
asked for a random 3 characters of if you g
Lloyds Bank - Dumb Password Rules
Max 15 characters, min 8. You cannot use **ANY** special characters - alpha-numerics only. This amazingly terrible password policy combines with a known phrase (The "Memorable Information") of which you will be asked for a random 3 characters of if you get your password right. This phrase has similar alpha-numeric restrictions applied.
dumbpasswordrules.com
November 14, 2025 at 3:04 AM
This dumb password rule is from Best Buy.

You can enter whatever password you like! But you probably don't want to
make it too long, because you'll break us and you'll never be able to
login again.

https://dumbpasswordrules.com/sites/best-buy/

#password #passwords #infosec #cybersecurity #dumbpas
Best Buy - Dumb Password Rules
You can enter whatever password you like! But you probably don't want to make it too long, because you'll break us and you'll never be able to login again.
dumbpasswordrules.com
November 13, 2025 at 2:42 PM
This dumb password rule is from Sunny Portal.

The password must consist of at least 10 and at most 50 characters. It must contain at least one special character, one number, one lower-case letter and one upper-case letter.
The following characters are permitted for the password:

- Lower-case lette
Sunny Portal - Dumb Password Rules
The password must consist of at least 10 and at most 50 characters. It must contain at least one special character, one number, one lower-case letter and one upper-case letter. The following characters are permitted for the password: - Lower-case letters (a-z) - Upper-case letters (A-Z) - Digits (0-9) - Special characters (!\"§$%&/()=?*+'#-_.:,;|{[]}²³^°)
dumbpasswordrules.com
November 13, 2025 at 3:05 AM
This dumb password rule is from Delta.

It's a good thing they don't store personal information such as your passport number... oh wait.

https://dumbpasswordrules.com/sites/delta/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
Delta - Dumb Password Rules
It's a good thing they don't store personal information such as your passport number... oh wait.
dumbpasswordrules.com
November 12, 2025 at 2:44 PM
This dumb password rule is from Canadian Imperial Bank of Commerce.

Letters and numbers only, no symbols. Also an undocumented maximum of 12 characters!

https://dumbpasswordrules.com/sites/canadian-imperial-bank-of-commerce/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
Canadian Imperial Bank of Commerce - Dumb Password Rules
Letters and numbers only, no symbols. Also an undocumented maximum of 12 characters!
dumbpasswordrules.com
November 12, 2025 at 3:03 AM
This dumb password rule is from Dnevnik.ru.

Silently (sic!) trim password to 30 symbols.

That causes the stupid case when you could successfully registrate an account with password length of 52 and can't login with the password.

https://dumbpasswordrules.com/sites/dnevnik-ru/

#password #password
Dnevnik.ru - Dumb Password Rules
Silently (sic!) trim password to 30 symbols. That causes the stupid case when you could successfully registrate an account with password length of 52 and can't login with the password.
dumbpasswordrules.com
November 11, 2025 at 2:43 PM
This dumb password rule is from A1 Mobile Serbia.

A1 mobile Serbia is a mobile provider in Serbia that imposes poor password rules.

Translation: "Length of the password must be between 8 and 20 characters and can only have letters and digits."

https://dumbpasswordrules.com/sites/a1-mobile-serbia/
A1 Mobile Serbia - Dumb Password Rules
A1 mobile Serbia is a mobile provider in Serbia that imposes poor password rules. Translation: "Length of the password must be between 8 and 20 characters and can only have letters and digits."
dumbpasswordrules.com
November 11, 2025 at 3:04 AM
This dumb password rule is from AOK (German Health Insurance).

This is the online customer portal of the German health insurance company AOK. They have an extensive set of rules for both passwords and usernames.
The password rules are:
- Length between 8 and 14 characters
- At least one letter, one
AOK (German Health Insurance) - Dumb Password Rules
This is the online customer portal of the German health insurance company AOK. They have an extensive set of rules for both passwords and usernames. The password rules are: - Length between 8 and 14 characters - At least one letter, one number and one special character - Special characters are: !@$%/=?`+@#_.;:{}| - The password must not start with ? or ! - The password must not include the username - The password must not be the same as any of your previous passwords The rules for the username are: - Length between 1 and 12 characters - No umlauts allowed (äöü), no special characters, no spaces, no ., no _, no ß
dumbpasswordrules.com
November 10, 2025 at 2:43 PM
This dumb password rule is from TreasuryDirect.

Will allow most passwords longer than 8 characters. Doesn't tell you there is a
maximum length of 16 characters. Then forces you to type it with an on-screen keyboard
with no capital letters.

https://dumbpasswordrules.com/sites/treasurydirect/

#pass
TreasuryDirect - Dumb Password Rules
Will allow most passwords longer than 8 characters. Doesn't tell you there is a maximum length of 16 characters. Then forces you to type it with an on-screen keyboard with no capital letters.
dumbpasswordrules.com
November 10, 2025 at 3:08 AM
This dumb password rule is from Irodoricomics.

A website to buy english-localized doujins. The password must be between 4 and 20 characters long

https://dumbpasswordrules.com/sites/irodoricomics/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
Irodoricomics - Dumb Password Rules
A website to buy english-localized doujins. The password must be between 4 and 20 characters long
dumbpasswordrules.com
November 9, 2025 at 2:41 PM
This dumb password rule is from GoDaddy.

Some characters are **too** special.

https://dumbpasswordrules.com/sites/godaddy/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
GoDaddy - Dumb Password Rules
Some characters are **too** special.
dumbpasswordrules.com
November 9, 2025 at 3:04 AM
This dumb password rule is from TwinSpires.

You can gamble on our site. We'll keep your money secure with a 12 character password!

https://dumbpasswordrules.com/sites/twinspires/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
TwinSpires - Dumb Password Rules
You can gamble on our site. We'll keep your money secure with a 12 character password!
dumbpasswordrules.com
November 8, 2025 at 2:41 PM
This dumb password rule is from Nintendo.

Password between 8-20 characters, at least two "categories" of characters, and cannot use the same character more than twice in a row. At least it supports MFA.

https://dumbpasswordrules.com/sites/nintendo/

#password #passwords #infosec #cybersecurity #du
Nintendo - Dumb Password Rules
Password between 8-20 characters, at least two "categories" of characters, and cannot use the same character more than twice in a row. At least it supports MFA.
dumbpasswordrules.com
November 8, 2025 at 2:59 AM
This dumb password rule is from MarketWatch.

- Cannot be longer than 15 characters.
- Must contain one number.
- Cannot contain spaces, %, & or +.

https://dumbpasswordrules.com/sites/marketwatch/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
MarketWatch - Dumb Password Rules
- Cannot be longer than 15 characters. - Must contain one number. - Cannot contain spaces, %, & or +.
dumbpasswordrules.com
November 7, 2025 at 2:43 PM
This dumb password rule is from GoDaddy.

Some characters are **too** special.

https://dumbpasswordrules.com/sites/godaddy/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
GoDaddy - Dumb Password Rules
Some characters are **too** special.
dumbpasswordrules.com
November 7, 2025 at 3:02 AM
This dumb password rule is from United Kingdom Post Office.

Will not allow you to copy-paste your password into the text box (e.g. from a password manager). Because allowing people to copy their passwords over will defintely not result in weak passwords :)

https://dumbpasswordrules.com/sites/unite
United Kingdom Post Office - Dumb Password Rules
Will not allow you to copy-paste your password into the text box (e.g. from a password manager). Because allowing people to copy their passwords over will defintely not result in weak passwords :)
dumbpasswordrules.com
November 6, 2025 at 2:43 PM
This dumb password rule is from Microsoft (e company store).

Max of 16 character oh and please don't use any characters we don'y know how to escape properly
also if it starts with ? you may break our wonderful website. What out with your password generator
duplicated characters is far too insecure
Microsoft (e company store) - Dumb Password Rules
Max of 16 character oh and please don't use any characters we don'y know how to escape properly also if it starts with ? you may break our wonderful website. What out with your password generator duplicated characters is far too insecure to allow here.
dumbpasswordrules.com
November 6, 2025 at 3:05 AM
This dumb password rule is from Vio Bank.

The password requirement is not even fully enumerated. Upon inspection of the source code, the following lines were found, hidden by javascript: "Must include at least %MINSPECIAL of the following characters:-.~!@#&_{}|:$%^*()=[];?/+"

The actual list of sp
Vio Bank - Dumb Password Rules
The password requirement is not even fully enumerated. Upon inspection of the source code, the following lines were found, hidden by javascript: "Must include at least %MINSPECIAL of the following characters:-.~!@#&_{}|:$%^*()=[];?/+" The actual list of special characters that are prohibited is correctly enumerated there. It's a result of [`a misapplication`](https://cibng.ibanking-services.com/cib/scripts/jquery/custsvc/custSvcChangePassword.js) of the [`variable allowedSpecialCharacters found here`](https://cibng.ibanking-services.com/cib/scripts/jquery/custsvc/fis-visual-validator.js?version=20180507). It took under 5 minutes to find the bug after looking at the source for the first time. This is a bank.
dumbpasswordrules.com
November 5, 2025 at 2:44 PM
This dumb password rule is from Waze.

After you request a password reset and you receive an email with instructions and link to reset your password, you are presented with this password reset form. Your password length is limited between 8 and 16 characters. Additionally the form breaks with an err
Waze - Dumb Password Rules
After you request a password reset and you receive an email with instructions and link to reset your password, you are presented with this password reset form. Your password length is limited between 8 and 16 characters. Additionally the form breaks with an error if you use any special characters. The form does not mention anything about special characters. Waze is owned by Google.
dumbpasswordrules.com
November 5, 2025 at 3:03 AM
This dumb password rule is from LCL.

You have to enter your 6-digit password using this Frenchy keypad.

https://dumbpasswordrules.com/sites/lcl/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
LCL - Dumb Password Rules
You have to enter your 6-digit password using this Frenchy keypad.
dumbpasswordrules.com
November 4, 2025 at 2:44 PM
This dumb password rule is from Arbeitnehmeronline.

Service for managing employment documents of the German company Datev.

Only the following character categories are allowed: Letters, numbers and this special
characters set: !#$%&()*+,-./:;<=>?@[\]^_`{|}~äöüßÄÖÜ

https://dumbpasswordrules.com/sit
Arbeitnehmeronline - Dumb Password Rules
Service for managing employment documents of the German company Datev. Only the following character categories are allowed: Letters, numbers and this special characters set: !#$%&amp;()*+,-./:;&lt;=&gt;?@[&#92;]^_`{|}~äöüßÄÖÜ
dumbpasswordrules.com
November 4, 2025 at 3:02 AM
This dumb password rule is from Bloomingdale's.

16 characters maximum, no `.` `,` `-` `|` `/` `=` or `_` allowed.

https://dumbpasswordrules.com/sites/bloomingdales/

#password #passwords #infosec #cybersecurity #dumbpasswordrules
Bloomingdale&#39;s - Dumb Password Rules
16 characters maximum, no `.` `,` `-` `|` `/` `=` or `_` allowed.
dumbpasswordrules.com
November 3, 2025 at 2:43 PM
This dumb password rule is from SAS Eurobonus.

The best thing about rules, is that you can multiple different ones!
Like SAS that allows you to have a long password at least when signing
up, but you'll be sorry if you want to change your password later on.

https://dumbpasswordrules.com/sites/sas-e
SAS Eurobonus - Dumb Password Rules
The best thing about rules, is that you can multiple different ones! Like SAS that allows you to have a long password at least when signing up, but you&#39;ll be sorry if you want to change your password later on.
dumbpasswordrules.com
November 3, 2025 at 3:07 AM