PassFail.wtf

Blog

Research, analysis, and commentary on password security and authentication policies.

Featured

We Graded the Password Policies of the Fortune 100 — The Results Are Embarrassing

We systematically tested and graded the password and authentication policies of America's largest consumer-facing companies. What we found should concern you.

PassFail Team·March 31, 2026·12 min read·
researchfortune-100password-policy

How We Grade: The PassFail Methodology

A full explanation of our 10-category rubric, the NIST standards we reference, and why we score things the way we do.

PassFail Team·March 31, 2026·8 min read·
methodologyrubricnist

Why Your Bank Still Limits You to 12 Characters

Banks are the worst password policy offenders in our dataset. Here's why, and what it means for your security.

PassFail Team·March 31, 2026·6 min read·
bankinghall-of-shameanalysis

Stay ahead of policy changes

New audits, policy changes, and security research — no spam.