Password Shamer

Shaming bad password requirements and practices everywhere.

What is this?

Arduous and complicated password rules actually reduce web security. What ultimately makes a password strong is its length, not a series of difficult to remember rules. Password rules that disallow or restrict the use of special characters interfere with the entropy of the passwords stored in applications, making them easier to reverse engineer and crack.

Many people today use password managers, such as 1Password, which generate long and randomized passwords. Restrictive password rules prevent your users from benefiting from these secure passwords.

Besides a case for a bare minimum of complexity for a password, including a minimum length, your password rules are likely ineffective and actually reduce the security of your application. Stop it. Do better.

This is a repository of sites, apps, and entities which violate this manifesto.

“Password rules are bullshit.” - Jeff Atwood

Contribute to this project

If you have an update to this list, email me via my contact form or create a pull request on GitHub.

If you are affiliated with one of the companies or sites linked above and you're unhappy, check yourself before you wreck yourself. Then you can email me via my contact form and I can take a look.