Breaking Contract By Forcing Password Change

palswim

Golden Member
Nov 23, 2003
1,049
0
71
www.palswim.net
I've just about had it with web sites that increase their password complexity requirements and force you to change your current password if it does not comply. I don't need an explanation as to why they do it; suffice it to say that I do not agree.

Websites that I use with whom I do not have a contract (i.e. anything for free) can do this, and I either can discontinue my use of the service or take it and change my password.

However, with contract (basically, agreements to pay for a service for a certain number of months, e.g., cell phone providers) services, some companies still try to do this. In my thinking, this essentially breaks the contract by fundamentally altering my service by requiring me to do something to which I never agreed.

Again, if the company doesn't force you to change your password, but enforces complexity requirements if you ever change/reset your password (Google does this), I do have to take it. I wish they didn't, but I can't do too much about that. I only believe I have a leg on which to stand where the company forces me to change the password by preventing me from doing anything on the site before changing the password.

What are your thoughts? Or, how much leverage do I have? (I expect a lot of IANAL responses, but that's quite all right. Maybe we'll even have some IAAL responses!)
 

ElFenix

Elite Member
Super Moderator
Mar 20, 2000
102,425
8,388
126
It's their fault if there is a security breach with your data by you using a weak pw. They need to cover their bases.

yes but a lot of times what they enforce is not strong password, just one that's hard to remember.

how strong is a 6 character password regardless of special characters, numbers, and case?
 

silverpig

Lifer
Jul 29, 2001
27,709
11
81
What I hate is when they say something like "your password has to be between 6-10 characters, and contain at least 1 upper case, 1 lower case, and 1 numerical character"

FU

I don't have a single password, rather an internal password algorithm that I use for every website. These kind of restrictions mess it up.
 
Oct 20, 2005
10,978
44
91
What I hate is when they say something like "your password has to be between 6-10 characters, and contain at least 1 upper case, 1 lower case, and 1 numerical character"

FU

I don't have a single password, rather an internal password algorithm that I use for every website. These kind of restrictions mess it up.

Don't forget "You cannot use your last 5,000,000 passwords".

F THAT S.

I have like 4-5 password combos I like to cycle through, but nowadays that doesn't work because I can't use the last 5M passwords.
 

MotionMan

Lifer
Jan 11, 2006
17,312
12
81
Don't forget "You cannot use your last 5,000,000 passwords".

F THAT S.

I have like 4-5 password combos I like to cycle through, but nowadays that doesn't work because I can't use the last 5M passwords.

Yeah. This one bugs me, too. Especially when I don't want to change the password - I just need a reminder of which password I used for this site.

MotionMan
 

Bignate603

Lifer
Sep 5, 2000
13,897
1
0
I knew one guy that was complaining about his work password. Apparently he couldn't use anything in his password that was a word. For example, if you tried xY1%34cAt5!aJ it would be rejected because it has "cat" in it. It got so frustrating that he ended up using a klingon dictionary to pick passwords.
 

MotionMan

Lifer
Jan 11, 2006
17,312
12
81
I knew one guy that was complaining about his work password. Apparently he couldn't use anything in his password that was a word. For example, if you tried xY1%34cAt5!aJ it would be rejected because it has "cat" in it. It got so frustrating that he ended up using a klingon dictionary to pick passwords.

It was not that bad at my dad's work. However, he would have to change his password once a WEEK, it had to have at least one capital and 1 number and a password could not be repeated for a year.

He would hang the 49ers team picture on his wall and start from the first guy in the first row and work his way through the picture until the next years picture came out (i.e. "Montana16", "Rice80", etc.)

MotionMan
 

Doppel

Lifer
Feb 5, 2011
13,306
3
0
How companies deal with passwords is very irritating, but if u think u will get out of a cell contract because the compan is forced u to change ur password, absolutely not. Good luck with that.
 

Doppel

Lifer
Feb 5, 2011
13,306
3
0
It was not that bad at my dad's work. However, he would have to change his password once a WEEK, it had to have at least one capital and 1 number and a password could not be repeated for a year.

He would hang the 49ers team picture on his wall and start from the first guy in the first row and work his way through the picture until the next years picture came out (i.e. "Montana16", "Rice80", etc.)

MotionMan
Everyone I know forced,to change password at work simple adds another digit on the end, I.e. bob11, bob12, etc.

It took me forever to pick a password for USPS.com, whatever their requirements are are freaking retarded.
 

HybridSquirrel

Diamond Member
Nov 20, 2005
6,161
2
81
I find using a phrase is the best way to remember a password....for example thatchickisfat....or with the guidelines at work 8tH4tch1ck15f47


new password guidelines are easy if you are fluent with leet speak
 

FoBoT

No Lifer
Apr 30, 2001
63,089
12
76
fobot.com
where i work, we recently changed our access protocol to certain key servers
our accounts are now 'normally' locked for servers in these key zones
each time we need access, you have to email either our manager for any access not pertaining to an approved change (under the change control system) or if it is for an approved change, we email the ops center directly referencing the approved change. then they email us back after our account is reset telling us to call them to get the new password. then we can logon, but the system then immediately requires us to change the password during the logon. once we change it again, then we can get onto the server to make the changes. access is automatically removed and our account again locked after the specified time, normally 2-8 hours is allowed

it is very nice how inefficient it is and how much extra time it takes us to do things now.
 

ChopperDave

Senior member
May 4, 2012
216
0
0
I don't think this holds logic at all because you haven't said exactly how these password requirements break your contract.

Password requirements suck I agree so I just use lastpass. It kicks butt and I don't have to remember the email I used the username I used or the password I used because it just fills everything in.
 
Feb 6, 2007
16,432
1
81
Encouraging complex passwords has the side effect of encouraging employees to write their passwords down on Post-it notes and paste them to their monitor/laptop, which completely defeats the purpose of having a password in the first place.
 

DaTT

Garage Moderator
Moderator
Feb 13, 2003
13,295
118
106
Encouraging complex passwords has the side effect of encouraging employees to write their passwords down on Post-it notes and paste them to their monitor/laptop, which completely defeats the purpose of having a password in the first place.

This. I don't see the point of ever having to change your password if it has never been compromised.
 

pontifex

Lifer
Dec 5, 2000
43,806
46
91
i have like 6 different passwords at work and there's absolutely no reason for it.

also love all the stupid time wasting processes we have to follow because some people can't do their jobs properly.
 

ultimatebob

Lifer
Jul 1, 2001
25,135
2,445
126
i have like 6 different passwords at work and there's absolutely no reason for it.

also love all the stupid time wasting processes we have to follow because some people can't do their jobs properly.

Yeah, and the rules seem to differ on all of them. Some systems require no password changes at all (EVER!), yet others require a 9 character password that needs numbers, and mixed case, AND a special character, AND need to be changed every 45 days.

The passwords for the latter systems are the ones that I have to write down to remember... and I doubt that I'm the only one.
 

alent1234

Diamond Member
Dec 15, 2002
3,915
0
0
used to work for a government agency that did that. not only did the user name consist of a crazy combination of your initials, office,and department. but they would change the password twice a year and assign random ones to people. 8 characters, casing, special character, etc. lots of people would write it down. the james bond wannabe IT people thought they were cool
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |