Dumb Password Rules<p>This dumb password rule is from Scandinavian Airlines.</p><p>The password rules itself is fine, but, it doesn't inform about the max length of the password.<br>Their max length is 14 characters, so even if you enter a password of 42 chars, you can login with the first 14 of it.<br>In this case, I changed my password to **Super_l0ng_password_that_fits_all_criteri...</p><p><a href="https://dumbpasswordrules.com/sites/scandinavian-airlines/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">dumbpasswordrules.com/sites/sc</span><span class="invisible">andinavian-airlines/</span></a></p><p><a href="https://infosec.exchange/tags/password" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>password</span></a> <a href="https://infosec.exchange/tags/passwords" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passwords</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/dumbpasswordrules" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dumbpasswordrules</span></a></p>