Hellbound
Merchant of Doom
I like long passwords, preferrably the CorrectHorseBatteryStaple kind. At my current job they have a password management system that will ask you to change your password ever so often. This system limits the password to 8 letters, 2 characters and no punctuation...
Funny thing is, it is possible to "circumvent" this system by changing your password using the ordinary Windows functionality. So I can have my 24 character password anyway.
At least IT doesn't ask for passwords. Not that I would tell them.
That's insane. Especially because in many cases an 8 character password is less secure than 7 characters, if NTLM is involved (and if they limit it, that suggests to me legacy software somewhere, which would make me suspect NTLM is still in use). It has to do with the way the hashes are broken up; basically it's 7 character chucks. That means an 8-char password has one char (the 8th) that only needs 26 attempts (36 with digits) to brute force. And knowing the last character can give a clue to the other 7.
