853
all 34 comments
sorted by: hot top new old
[-] Landless2029@lemmy.world 69 points 1 year ago

Never have this problem anymore with a password keeper. All new passwords are unique.

What REALLY pisses me off is when:

  • register for account
  • cannot register, account already exists
  • password reset
  • account not found
[-] Serinus@lemmy.world 36 points 1 year ago* (last edited 1 year ago)

I absolutely do. It's not that the password was wrong. It's that they wanted to invalidate all existing passwords and make you change it.

The easiest way to do that is for them to force everyone through the "forgot password" workflow. Zero or minimal code changes. They don't want to make a new, but very similar , "we had a security breach and are requiring you to change your password" workflow. They just don't care that they're blaming you for their problem.

[-] Vanilla_PuddinFudge@infosec.pub 13 points 1 year ago

We require our users use a password that is in between 8 and 14 characters, contains more than 2, but not exceeding 4 special characters, and at least 3 uppercase letters, 3 numbers with 0 repeating digits.

Generator: ".....fuck you?"

[-] Elgenzay@lemmy.ml 15 points 1 year ago

And while requiring special characters, they only allow some special characters. So you just turn off special characters in the generator and then add an exclamation mark at the end

[-] HeyThisIsntTheYMCA@lemmy.world 9 points 1 year ago

i just want to use ☭ and so few websites let you

[-] SacralPlexus@lemmy.world 6 points 1 year ago
[-] gingersaffronapricat@lemm.ee 2 points 1 year ago

Aaah. I made it so far but I was defeated by chess!

[-] TachyonTele@lemm.ee 9 points 1 year ago

This is more of a work computer issue than an personal computer one.

[-] LouSlash@sh.itjust.works 2 points 1 year ago

Basicly every terrible website/service that "irreversibly deletes" an account

[-] orca@orcas.enjoying.yachts 28 points 1 year ago

Here’s my recent favorite:

  • Try to log into site
  • Tells me my password is wrong… uhh okay
  • Try to reset password by auto-filling a new one from my password manager
  • New password set successfully! Yay!
  • Try to login again… fail. Wrong password… fucking what…?
  • Realize that their password field was clipping the password length off at some max length not fucking mentioned anywhere, so I have no clue what the actual password is without trial-and-erroring, which then results in an account lockout again

I’m a programmer and this kind of blatant stupidity from massive companies pisses me off to no end. MAKE YOUR PASSWORD REQUIREMENTS CLEAR. MAKE YOUR UX CLEAR.

[-] MisterFrog@lemmy.world 12 points 1 year ago

Maximum password lengths at anything below 64 characters grinds my gears.

Signed up for a bank account once that limited you to 12 characters. 12. And you could only chose from like 4 special characters.

No 2FA. No no. But the customer service agent pointed out they require you to also use a 6 digit second password!

That's a 18 digit password where 6 of them must be numbers.

Absolute travesty.

[-] d00phy@lemmy.world 11 points 1 year ago
  • Doesn't show password requirements until after first attempt is rejected
  • Password expiration w/o any alert
  • Arbitrary password length requirements (specifically max length)
  • Arbitrary character requirements (particularly disallowing or only allowing a certain subset of special characters)
  • Only offering SMS as "2FA"
  • Using email "2FA" on every. Login. Attempt. And offering no real 2FA alternative.

All of these are reasons I will look to move my business to a competitor.

[-] Scotty_Trees@lemmy.world 23 points 1 year ago

I hate how too real this has been...lol

[-] Almacca@aussie.zone 13 points 1 year ago

Fucking Spotify. Tried to reset my password - 'There is no record of this email address' Tried to make new account with same email - 'You cannot create a new account with an existing email' :|

[-] HeyJoe@lemmy.world 12 points 1 year ago

That's why you didn't remember. You did this before and made some 1 off password and you will never remember those 1 off passwords.

[-] CidVicious@sh.itjust.works 9 points 1 year ago

As a vpn user and a password manager user, for me it's often because a website decided to lock the account of anyone coming from a blacklisted IP.

Every single time

[-] wowwoweowza@lemmy.world 2 points 1 year ago

So been here!

[-] technomad@slrpnk.net 1 points 1 year ago

I've often encountered this when a website forces you to change/update passwords too.

[-] MentalEdge@sopuli.xyz 1 points 1 year ago* (last edited 1 year ago)

This happens because you're trying to re-use a previous password, which is not necessarily the current password.

The new password can't be same as any of your previous ones.

[-] dual_sport_dork@lemmy.world 19 points 1 year ago

More likely it's happening because the password change field silently truncates your input and the login field doesn't, or vise-versa, because whoever designed the web page or system is stupid.

[-] MentalEdge@sopuli.xyz 1 points 1 year ago* (last edited 1 year ago)

That is a possibility. But then actually setting a completely new password shouldn't work, yes? Because when you go to use it, it won't work.

I doubt that's the "more likely" scenario.

Tons of people have reset a login more than once, and then forget, which is what leads to this scenario.

When they forget the new password, but re-remember a previous one, they try to use it to log in. When that fails, they go to reset it again, and they try to set it back to the password they remember. Which doesn't work, because it is a previous password. But at the same time it is also not the current one.

The supposed catch 22 is that if it can't be their new password, it should work to log in. And if it can't be used to log in, then they should be able to set it as their password.

In reality the password has already been used, but before a previous reset. So it is neither a valid new password, nor the current password. This does not occur to people.

This can happen in any correctly configured service that prevents password re-use, and is therefore the far more likely scenario.

[-] piefood@feddit.online 1 points 1 year ago

/me glares at ADP

I use a password manager, which auto-types the password, and I still have this happen to me.

[-] sqw@lemmy.sdf.org -1 points 1 year ago

hash collision

this post was submitted on 24 Apr 2025
853 points (98.7% liked)

Comic Strips

23491 readers
2207 users here now

Comic Strips is a community for those who love comic stories.

Rules
  1. 😇 Be Nice!

    • Treat others with respect and dignity. Friendly banter is okay, as long as it is mutual; keyword: friendly.
  2. 🏘️ Community Standards

    • Comics should be a full story, from start to finish, in one post.
    • Posts should be safe and enjoyable by the majority of community members, both here on lemmy.world and other instances.
    • Any comic that would qualify as raunchy, lewd, or otherwise draw unwanted attention by nosy coworkers, spouses, or family members should be tagged as NSFW.
    • Moderators have final say on what and what does not qualify as appropriate. Use common sense, and if need be, err on the side of caution.
  3. 🧬 Keep it Real

    • Comics should be made and posted by real human beans, not by automated means like bots or AI. This is not the community for that sort of thing.
  4. 📽️ Credit Where Credit is Due

    • Comics should include the original attribution to the artist(s) involved, and be unmodified. Bonus points if you include a link back to their website. When in doubt, use a reverse image search to try to find the original version. Repeat offenders will have their posts removed, be temporarily banned from posting, or if all else fails, be permanently banned from posting.
    • Attributions include, but are not limited to, watermarks, links, or other text or imagery that artists add to their comics to use for identification purposes. If you find a comic without any such markings, it would be a good idea to see if you can find an original version. If one cannot be found, say so and ask the community for help!
  5. 📋 Post Formatting

    • Post an image, gallery, or link to a specific comic hosted on another site; e.g., the author's website.
    • Meta posts about the community should be tagged with [Meta] either at the beginning or the end of the post title.
    • When linking to a comic hosted on another site, ensure the link is to the comic itself and not just to the website; e.g.,
      ✅ Correct: https://xkcd.com/386/
      ❌ Incorrect: https://xkcd.com/
  6. 📬 Post Frequency/SPAM

    • Each user (regardless of instance) may post up to five (5 🖐) comics a day. This can be any combination of personal comics you have written yourself, or other author's comics. Any comics exceeding five (5 🖐) will be removed.
  7. 🏴‍☠️ Internationalization (i18n)

    • Non-English posts are welcome. Please tag the post title with the original language, and include an English translation in the body of the post; e.g.,
      Sí, por favor [Spanish/Español]
  8. 🍿 Moderation

    • We are human, just like most everybody else on Lemmy. If you feel a moderation decision was made in error, you are welcome to reach out to anybody on the moderation team for clarification. Keep in mind that moderation decisions may be final.
    • When reporting posts and/or comments, quote which rule is being broken, and why you feel it broke the rules.
Banned Artists

The following artists are banned from the community.

  1. Jago
  2. Stonetoss

It should be noted that when you make reports, it is your responsibility to provide rational reasoning why something should be removed. Saying it simply breaks community rules is not always good enough.

Web Accessibility

Note: This is not a rule, but a helpful suggestion.

When posting images, you should strive to add alt-text for screen readers to use to describe the image you're posting:

Another helpful thing to do is to provide a transcription of the text in your images, as well as brief descriptions of what's going on. (example)

Web of Links

founded 2 years ago
MODERATORS