top | item 12240271

(no title)

lips | 9 years ago

Does anyone aside from HN type folks listen to these recommendations?

I just had a major banking institution send me a plaintext pw instead of reset token, with a 15 char limit, and a rotation requirement.

discuss

order

perlgeek|9 years ago

> Does anyone aside from HN type folks listen to these recommendations?

Probably not. But if you work as a contractor for somebody with non-sensical requirements, at least you have some research that you can link to to support your point.

eitland|9 years ago

I raise with a big client that reset my password to CompanyName123 and didn't let me change it.