At Bugzilla, I typed a new password that met the requirements stated on the account creation page. But I received:
The password does not meet our security requirements for the
following reason: not enough different characters or classes
For the sake of reproducible example, password attempt can be: “Qazxswedc123” – I got same message for that one too.
Web search found Does bugzilla.mozilla.org’s “new” password requirements make sense for that type of account/service? however those question was different.
https://wiki.mozilla.org/BMO/UserGuide/Passwords
must be at least 12 characters in length
must not contain parts of your email address, or your real name
must be complex, which means:
must be a passphrase of at least four words
OR
must contain a mixture of letters and symbols, containing characters from 3 out of the following 4 character classes:
lowercase letters, uppercase letters, numbers, and other symbols
P.S. they could have at least pretended to have a valid reason, “must not contain parts of your email address” may mean any letter from the address.
I’m trying to contact Mozilla via other means, maybe they accept it as a bug.
Continue reading Is it necessary for security to have undisclosed password requirements? [closed]→