Password Length Policy
8–24 chars
Character & Composition Rules
Silently rejects & character; manual email verification required
Multi-Factor Authentication
SMS 2FA available
Anti-Pattern Penalties
Password Manager Compatibility
Breach Response & Credential Hygiene
Password length restrictions are too tight
Allow minimum 8 chars, support up to at least 64 characters (preferably unlimited)
Reference: NIST SP 800-63B §5.1.1
Overly restrictive character rules
Accept all printable ASCII and Unicode characters. Remove composition requirements (no "must contain uppercase + number")
Reference: NIST SP 800-63B §5.1.1
Weak or missing MFA support
Implement TOTP (authenticator apps) and FIDO2/WebAuthn hardware keys. Work toward passkeys as a passwordless option
Reference: NIST SP 800-63B §4.3.1
No breach detection
Check new passwords against known-breached lists (e.g. HaveIBeenPwned API). Notify users of relevant breaches
Reference: NIST SP 800-63B §5.1.1.2
Help the community by testing this policy yourself. Earn +5 karma for each verification.