Outrageous Password Requirements
June 15, 2011 – 7:34 pmI was recently trying to sign up for an account on the website of one of my favorite podcast/radio shows, This American Life. As I was doing so, I used one of my “low security” passwords in the registration form. I decided to use one of my low security passwords because:
- The site is not secured with HTTPS, so the password will travel across the internet unencrypted anyway, and
- None of my personal information, other than the podcasts that I’ve already listened to, will be associated with this account – no credit card numbers, social security numbers, or even telephone number!
When I tried to click “Register” though, I got an error. Apparently, in addition to the numeral and random characters that are in my password, I have to also have both upper and lowercase letters, and also a symbol! Why are they enforcing these outrageous password requirements that, to be frank, many far-more-important internet commerce websites do not even enforce. This is a counterproductive practice that will require me to write down my password, which at the end of the day is less secure than the password that I tried to input in the first place!
This American Life, please fix your website.
I love the feature of the 




