Either my name, my password or my soul is invalid – but which?


I just don't understand why so many sites try to force you to weaken your passwords by specifying you must have at least one upper case character one number and one non alphanumeric character. there are ten numbers, there are in reality something like 16 special characters that is ever likely to get used...

Just enforce a decent length password. and for the love of god don't limit the password length at say 32 characters, if the function you use to hash the password can't handle arbitrary long input (within reason) then fix your hash function don't force the user to limit the password.

