venta: (Default)
[personal profile] venta

The other day, I was trying to sign into my Subway loyalty app. That's Subway the sandwich shop. They've changed their security model, and please would I pick a new password.

I have a generic password that I use for everything I don't really care about. It's a decent enough password (the sort of sites that tell you how strong your choice is usually put it at medium).

Subway rejected it: it had no capital letters. I tried a different one, which was rejected due to having no numbers. Ok, fine. I'll stick a capital in my generic password, and I'll doubtless forget I've done that and have to reset it in the future, but really who cares.

Subway rejected it because it had consecutive repeated characters. Wait, what? Does that rule actually achieve anything other than massively reducing the search space a potential hacker needs to hit?

To be honest, this is my feeling about all the "must have a capital", "must have a numerical digit" rule. It's quite possible to produce a strong password with neither. By enforcing these, you're just making my password very slightly easier to brute force.

Of course, given the general approach to passwords (see Ashley Madison's list of cracked passwords) I appreciate that the rules are there for a reason.

But "no repeated letters"? I don't get it.

This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

Profile

venta: (Default)
venta

December 2025

S M T W T F S
 123456
78910111213
14151617181920
212223 24252627
28293031   

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 5th, 2026 08:06 pm
Powered by Dreamwidth Studios