It’s infuriating to create a “strong password” with letters, numbers, upper and lowercase, symbols, and non-repeating text… but it has to be only 8 to 16 characters long.
That’s not a “strong” password, random characters or not.
Is there a limitation that somehow prevents these sites from allowing more than 16 characters?
I’m talking government websites, not just forums. It seems crazy to me.
Irá usually bad backend design, bad frontend design, all made by people who are only vaguely aware of security, and how it works.
It’s the same bunch that brought us “change your password every two weeks” and other insane anti security designs. They make it worse without even realizing it.
Do hope that your passwords aren’t stored in plain text!