Ah, but then there are sites that require lower, caps, numbers, and not
only numbers but numbers in a sufficiently long numerical string, and
symbol characters.

Then they probably store it in plaintext. That's when you just want to
shoot the punters and be done with it.

My wife's university site demands an enormously lengthy passphrase, like
it's an encryption passkey. That's when you petition the government to
line them up and shoot them without even offering a cigarette. Thank
heavens for password managers. If it's a site that you need to log into
several times a day, such policies are atrocious.

My own university finally figured out that forcing a unique password
change every 3 months makes people *less* secure, because of the
resulting post-it note syndrome, and not more secure. And, you know,
because we don't work for the NSA. I'm not sure what the new interval is
(a year would seem reasonable), but it's been at least 6 months with the
same password for me. Good on them.

And THEN there's sites that are totally insignificant, where I don't even
care if someone hijacks my account. As you say, they don't even need
security. They all get "asDF12345!!" if they want to be dicks about it,
or "password" if they're just playing security theater.


