I have worked as a government contractor so I know how these things happen. You see something wrong and pass that info back upstream, but there are few incentive to actually make things work well, rather problems are considered,... well, problems. Not altogether different from commercial settings, except in that case the emphasis is on the bottom line, so there *is* an incentive to fix things that affect the bottom line.
So I'm trying to use a government site to file paperwork (etherwork?) relating to international shipments. My extremely complex password is forgotten (not supposed to write them down right?) So I am going through the process of setting it up again which involves a fax, two phone calls (one to me which I didn't get and a return call) and an email. I have to be on the web site so they can tell me to push the buttons that have always been there, so I assume they didn't enable the recovery function until I called although it could have been done with the email, no?
So before I get the second email with the activation code the person on the phone tells it to me and says I should write it down (not type it in), so I do. I enter it and get the next screen. When I tell her that, she is *off* the phone like wasps were chasing her.
So now I have to type a new password and I realize why I couldn't get my usual passwords to work. I have a junk pw for junk yahoo accounts and the like, a moderate complexity pw for most "high" security sites (or anal ones that want to pretend they have decent security, but no one cares) and a highly complex pw for bank accounts and the like. Although you aren't supposed to use the same pw for multiple accounts, it is just too hard to do otherwise.
So I'm on the government page and they want a password that is 12 chars long, not 11, not 13, 12 chars. It says it needs at least one alpha and at least one non-alpha character. It also needs 6 of those chars to not be repeated. The pw may not contain a "string" from the username (how long is a piece of string?). The pw may not contain any "common strings" such as 1234, 2468.
I'm all set, I type in my new, uber secure password meeting all the above criteria and I get an error that my pw contains dictionary words! I didn't think that was what they meant by "common strings"... So I change a char so the four letter dictionary word is no longer a dictionary word. It now tells me I still have the dictionary word error plus now I am getting an error about a lack of complexity with a new rule about using 3 of 4 character classes! They didn't say anything about needing uppercase chars before. So I throw in a couple of special chars... what? I'm now using chars that are not allowed???
WTF!!!??? It took me a couple more tries to eliminate anything of three or more letters that *might* be a word and to use just one of the *four* special chars listed on the error page and to include an upper case letter just to make sure... and success, I'm in.
The entire process has been complicated by the fact that they want the pw typed twice in a password boxes where you can't see what you are typing. For 8 chars, not a big deal, but by the time I'm getting to 12 chars I need to see it. So I use the browser search edit box as a convenient text editor and cut and paste. I've always wondered about the need to hide the pw I'm typing. Then when I get to the end they conveniently display a new page with my user name and my newly entered password so I can print it out!!!!!
Is it just me or are these people insane!!!???