samthegeek’s avatarsamthegeek’s Twitter Archive—№ 62,554

  1. …in reply to @listelian
    listelian BCBSIL It is likely they are using an old-school system Z (a lot of healthcare companies do, as does DoD for Tricare). I bet the passwords are properly escaped but someone is being overly cautious. That and/or this is an internal requirement that got applied globally.
    1. …in reply to @SamTheGeek
      listelian BCBSIL The latter is strongly implied by the prohibition of date/month info — to prevent people from using ‘Password!JAN’ every time they need to rotate it based on another outdated security perspective.