Hacker News new | ask | show | jobs
by lips 3597 days ago
Does anyone aside from HN type folks listen to these recommendations?

I just had a major banking institution send me a plaintext pw instead of reset token, with a 15 char limit, and a rotation requirement.

2 comments

> Does anyone aside from HN type folks listen to these recommendations?

Probably not. But if you work as a contractor for somebody with non-sensical requirements, at least you have some research that you can link to to support your point.

I raise with a big client that reset my password to CompanyName123 and didn't let me change it.