• d00phy@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    16 hours ago
    • Doesn’t show password requirements until after first attempt is rejected
    • Password expiration w/o any alert
    • Arbitrary password length requirements (specifically max length)
    • Arbitrary character requirements (particularly disallowing or only allowing a certain subset of special characters)
    • Only offering SMS as “2FA”
    • Using email “2FA” on every. Login. Attempt. And offering no real 2FA alternative.

    All of these are reasons I will look to move my business to a competitor.