I just tried to log into an account of mine and it took two tries to get it right.
About a year ago I tried to long on to this account and apparently they had implemented a new system that forces you to change your password every few months - and it has requirements for those passwords. You have to have upper and lower case letters in the password. You have to have at least one number and at least one symbol.
In the past I had a few passwords that I used. If I tried one and it didn't work, I tried another. If that one didn't work, I'd try capitalizing a particular letter (in case that was a requirement for that particular account). I could usually figure out the password before I reached the point of locking myself out of an account - I might not remember which one I just typed in to know for future reference, but I could usually figure it out before I was locked out.
Here's the thing, I don't typically use the type of password that would be easily figured out by a bad actor. I actually have some passwords that have all the required criteria I mentioned above. But the thing is, they don't require me to change them every few months. I mean, I get that companies want to make it difficult to access by a bad actor but when the user can't access the account? Now THAT'S a problem!
No comments:
Post a Comment