var json_comments = new Array("<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15583983\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=59206\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-59206-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=59206\">Juliekins</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15583983\"><abbr class=\"published\" title=\"2009-09-24T17:39:08-05:00\">September 24, 2009  5:39 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15583983);\">Moderate</a> |</span>	<script type=\"text/javascript\" src=\"http://consumerist.com/mt-static/plugins/Moderate/moderate.js\"></script>	<script type=\"text/javascript\">		successMsg = \"\";	</script><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15583983');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>This has driven me crazy for ages. They are constantly offering to \"make my account more secure,\" too, but instead of adhering to a non-idiotic password policy, the offer is instead to enroll me in some bullshit fee service that pays my bill if I get fired while hopping one one foot under a full moon with my hair on fire and I'm singing the Star Spangled Banner.</p><p>I like my Amex, but yeah, the password issue blows. Hard.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15583983, 'Juliekins')\">Reply</a></div>		<!-- if it's a top level category ' -->										<div class=\"num-replies\">4 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15585209\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=562864\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-562864-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=562864\">GuinevereRucker</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585209\"><abbr class=\"published\" title=\"2009-09-24T18:17:19-05:00\">September 24, 2009  6:17 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585209);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585209');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15583983\" rel=\"nofollow\">Juliekins</a>: On the other hand, I hate it when websites require security passwords that are difficult to remember and have to have certain things.</p><p>Enter Password:  frank</p><p>*Sorry, your password must be six or more characters*</p><p>Enter Password:  frankfrank</p><p>*Sorry, your password must contain at least one of !@#$%^&amp;*.</p><p>Enter Password:  frankfrank*</p><p>*Sorry, your password must contain at least one uppercase letter.</p><p>And so on... that bugs me just as much as requiring a simple password.  Please, large companies with overpaid IT guys with stupid ideas, let us choose our own passwords yah?</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585209, 'GuinevereRucker')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15594189\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=59206\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-59206-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=59206\">Juliekins</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15594189\"><abbr class=\"published\" title=\"2009-09-25T00:01:41-05:00\">September 25, 2009 12:01 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15594189);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15594189');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585209\" rel=\"nofollow\">GuinevereRucker</a>: I feel you. I'm actually an IT security professional and spend a lot of time working with end users, doing security awareness workshops, what have you. I find it infuriating when a site won't lay out password requirements and force you to guess, or when they have particularly onerous requirements (15 characters, upper/lower/number/special, changes every 30 days, etc). Allowing users to use a utility like KeePass or PasswordSafe can help bridge that gap--you can make passwords as complex as is required/allowed, and you don't have to memorize anything but the master passphrase for your archive file. I'd much rather see an end user jump into something like KeePass have them write their passwords on post-its.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15594189, 'Juliekins')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment\" id=\"comment-15589339\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=140241\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=140241\">XTC46</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15589339\"><abbr class=\"published\" title=\"2009-09-24T20:40:33-05:00\">September 24, 2009  8:40 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15589339);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15589339');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15585209\" rel=\"nofollow\">GuinevereRucker</a>: As one of those IT guys you seem to dislike so much, I can say with certainty that most people pick bad passwords when not told to do otherwise. I cant even count how many times ive guessed a clients password for their servers, routers, email accounts, etc. And then there were countless more that i was able to crack VERY quickly (minutes, not hours or days) with some basic software.</p><br /><p>Like it or not, its for your own protection.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15589339, 'XTC46')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15594230\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=59206\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-59206-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=59206\">Juliekins</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15594230\"><abbr class=\"published\" title=\"2009-09-25T00:04:37-05:00\">September 25, 2009 12:04 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15594230);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15594230');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15589339\" rel=\"nofollow\">xtc46 - thinksmarter on twitter</a>: The challenge, though is getting your users to buy into the idea that a strong password with an X days change interval is good for <i>them.</i> I can assure you they only think you're doing it to protect \"your\" stuff. Getting out there in front of your users, engaging them, helping them understand how they fit into the process (and how IT fits into the business) will go a long way towards getting them to not hate you for asking them to change their passwords and use the occasional ! or @ in the damn things.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15594230, 'Juliekins')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15594902\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=140241\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=140241\">XTC46</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15594902\"><abbr class=\"published\" title=\"2009-09-25T00:41:42-05:00\">September 25, 2009 12:41 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15594902);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15594902');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15594230\" rel=\"nofollow\">Juliekins</a>: Getting people to understand just how important some things are is the most difficult part. The best way that i have found is to include them in the planning of things like this when possible and listen when they have concerns. But sometimes, we do have to be the bad guy and just force certain things.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15594902, 'XTC46')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15585621\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=224192\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-224192-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=224192\">johnva</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585621\"><abbr class=\"published\" title=\"2009-09-24T18:31:14-05:00\">September 24, 2009  6:31 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585621);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585621');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585209\" rel=\"nofollow\">GuinevereRucker</a>: The reason that places have those kinds of policies is because study after study has shown that a significant percentage of people choose very weak passwords when no restrictions are placed on them. As long as we're still using passwords as authentication measures, there's going to be a tension between security and the usability problems you mention.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585621, 'johnva')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584108\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=235750\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-235750-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=235750\">zomgorly</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584108\"><abbr class=\"published\" title=\"2009-09-24T17:43:10-05:00\">September 24, 2009  5:43 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584108);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584108');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I wish I could remember the credit company that I use that has the same exact policy that I found was very odd considering how secure some sites are with log ins and don't deal with my finances.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584108, 'zomgorly')\">Reply</a></div>		<!-- if it's a top level category ' -->										<div class=\"num-replies\">4 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15621974\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=133145\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-133145-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=133145\">tcolberg</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15621974\"><abbr class=\"published\" title=\"2009-09-26T03:48:01-05:00\">September 26, 2009  3:48 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15621974);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15621974');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15584108\" rel=\"nofollow\">zomgorly</a>: Charles Schwab's site also has the same problem.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15621974, 'tcolberg')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment\" id=\"comment-15589002\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"http://\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a title=\"http://\" href=\"http://\" rel=\"nofollow\">sn1per</a>    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15589002\"><abbr class=\"published\" title=\"2009-09-24T20:28:43-05:00\">September 24, 2009  8:28 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15589002);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15589002');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15584108\" rel=\"nofollow\">zomgorly</a>: Chase has the \"no special characters\" rule, and I think they have a minimum and maximum length too, but it's not as restrictive as this one. However, Chase also has some way of remembering what computers have been used to log into the account, and requires a telephone authentication when logging on from a new computer, so that's kept me from complaining too much. Still, I always wondered why a credit card company would set either minimum or maximum password lengths, as all it does is make a brute force easier.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15589002, 'sn1per')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15592151\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=352646\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-352646-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=352646\">nybiker</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15592151\"><abbr class=\"published\" title=\"2009-09-24T22:23:52-05:00\">September 24, 2009 10:23 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15592151);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15592151');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15589002\" rel=\"nofollow\">sn1per</a>: That Chase 'feature' isn't so much a feature as a PITA since I delete all cookies from all my browsers, so every time I log in to check my statement, it's 'oh, you're on a new computer, please let us call you to tell you the new auth code.'</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15592151, 'nybiker')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15586053\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=428567\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-428567-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=428567\">zlionsfan</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15586053\"><abbr class=\"published\" title=\"2009-09-24T18:45:05-05:00\">September 24, 2009  6:45 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15586053);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15586053');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15584108\" rel=\"nofollow\">zomgorly</a>: Citibank? My mortgage was bought by Citi a few years ago, and I remember trying to use a better password and being denied. (In fact, IIRC, it didn't tell me why my password was unacceptable, it just didn't let me submit it. I had to use my developer brain to guess that it wanted only numbers and letters.)</p><p>Although now my Citi password is longer than 8 characters, so it may not be an exact match ...</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15586053, 'zlionsfan')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584117\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=87183\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-87183-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=87183\">citking</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584117\"><abbr class=\"published\" title=\"2009-09-24T17:43:21-05:00\">September 24, 2009  5:43 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584117);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584117');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Our corporate US Bank site is similar to this - I can't use special characters, only letters (upper and lower thankfully) and numbers. They also expire every 30 days, it has to start with a letter, and you can't use the same passwords within a year. I understand the year part, but seriously, no special characters??</p><p>There is no good reason on earth why a password cannot contain certain characters or has to start with a letter or can only be x characters long. Ciphers don't care what is in a password. The only reason many companies disallow the use of spaces, special characters, length, etc. is lazy programming - programmers don't sanitize text input properly and are all worried that someone might break their DB should a \"Bobby Tables\" get into the system.</p><p>One thing I love about Windows and Linux passwords: They can contain whatever you can throw at them: spaces, symbols, alt codes, you name it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584117, 'citking')\">Reply</a></div>		<!-- if it's a top level category ' -->									<div class=\"num-replies\">3 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15584498\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=436259\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-436259-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=436259\">MostlyHarmless</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584498\"><abbr class=\"published\" title=\"2009-09-24T17:55:23-05:00\">September 24, 2009  5:55 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584498);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584498');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15584117\" rel=\"nofollow\">citking</a>: Little bobby tables!</p><p>One more comment like that and I wont have any option but to heart you ;)</p><p>Speaking of which, I just got the Volume 0 of the xkcd book on tuesday. The annotations and side notes are worth it (for the unsigned version anyways).</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584498, 'MostlyHarmless')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15584182\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=87183\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-87183-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=87183\">citking</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584182\"><abbr class=\"published\" title=\"2009-09-24T17:45:27-05:00\">September 24, 2009  5:45 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584182);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584182');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15584117\" rel=\"nofollow\">citking</a>: And for those not getting the Bobby Tables reference: <a href=\"http://xkcd.com/327/\" rel=\"nofollow\">[xkcd.com]</a></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584182, 'citking')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15592199\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=352646\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-352646-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=352646\">nybiker</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15592199\"><abbr class=\"published\" title=\"2009-09-24T22:25:41-05:00\">September 24, 2009 10:25 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15592199);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15592199');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15584182\" rel=\"nofollow\">citking</a>: Thx. That's precious.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15592199, 'nybiker')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584123\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=436259\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-436259-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=436259\">MostlyHarmless</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584123\"><abbr class=\"published\" title=\"2009-09-24T17:43:36-05:00\">September 24, 2009  5:43 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584123);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584123');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Hmmm my Amex login does not have any such limitations... My password is in the double digits. Though now that I think of it, it does not have any special characters... Not that it makes a difference with a password that convoluted.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584123, 'MostlyHarmless')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584175\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1340486\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-1340486-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1340486\">holytrainwreck</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584175\"><abbr class=\"published\" title=\"2009-09-24T17:45:19-05:00\">September 24, 2009  5:45 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584175);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584175');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>No special characters just limits the possible character combinations that can be used for passwords to the 26 letters plus numbers 0-9. How can that be MORE secure?</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584175, 'holytrainwreck')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584215\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=429538\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-429538-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=429538\">Preyfar</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584215\"><abbr class=\"published\" title=\"2009-09-24T17:46:34-05:00\">September 24, 2009  5:46 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584215);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584215');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Yeah. It's been like that for about over a year now, too. When I signed up for AMEX Plum card (free hotel nights - makes traveling and conventions dirt cheap!) they did the same thing. I was forced to choose a password that was obnoxiously stupid.</p><p>You can still do some secure passwords, but it's just not the same.</p><p>Then again, I stopped caring about my AMEX card after they dropped my credit limit by $5K... while I was staying at a hotel and the card got reject /for the room I was already staying in/. Oh, and I never got a warning, notice, e-mail, latter, etc. about my reduced limit for that. Then every time I paid off the card they dropped it by $200 here, $200 there. It's ridiculous.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584215, 'Preyfar')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584273\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=27359\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-27359-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=27359\">Tamar Weinberg</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584273\"><abbr class=\"published\" title=\"2009-09-24T17:48:24-05:00\">September 24, 2009  5:48 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584273);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584273');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I tweeted about this a few weeks ago.  I had a 15-character password ready to go and had to restrict it to the shorter version (which I forgot, actually, come to think of it).</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584273, 'Tamar Weinberg')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584296\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1225465\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-1225465-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1225465\">Sunshine1970</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584296\"><abbr class=\"published\" title=\"2009-09-24T17:49:09-05:00\">September 24, 2009  5:49 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584296);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584296');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I've wondered that too. When all my other passwords for other sites are random letters, numbers, special characters, this one is 8 characters long. I made it as random as possible, but I don't feel too secure with it...</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584296, 'Sunshine1970')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584300\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=918136\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-918136-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=918136\">bitslammer</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584300\"><abbr class=\"published\" title=\"2009-09-24T17:49:19-05:00\">September 24, 2009  5:49 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584300);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584300');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Yep...out of all my online accounts I find it funny that my AMEX password is the LEAST secure...less secure than the one I use to login to this site.</p><p>I've sent a couple of emails but they seem to fall on dead ears. It's a shame too because I like my AMEX card because it's through Costco and I like the perks.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584300, 'bitslammer')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584371\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=129982\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-129982-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=129982\">jaredutah</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584371\"><abbr class=\"published\" title=\"2009-09-24T17:51:27-05:00\">September 24, 2009  5:51 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584371);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584371');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Even my local credit union has better online password policies than my AMEX Blue Card.  In fact, out of all my online banking/financial accounts, my AMEX Blue Card has the least password security.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584371, 'jaredutah')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584377\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=132151\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-132151-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=132151\">ExtraCelestial</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584377\"><abbr class=\"published\" title=\"2009-09-24T17:51:38-05:00\">September 24, 2009  5:51 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584377);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584377');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>But if there is a security breach and the perps go on a shopping spree with the account info they obtain, wouldn't Amex be the only one footing the bill?</p><br /><p>Or are we concerned that the information can lead to even more sensitive information like SS#s and new accounts with other lenders? I know nothing about web security.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584377, 'ExtraCelestial')\">Reply</a></div>		<!-- if it's a top level category ' -->							<div class=\"num-replies\">1 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15587883\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=161466\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-161466-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=161466\">yagisencho</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15587883\"><abbr class=\"published\" title=\"2009-09-24T19:50:49-05:00\">September 24, 2009  7:50 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15587883);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15587883');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15584377\" rel=\"nofollow\">TinkishDelight</a>:</p><br /><p>I believe that you are asked to agree to their Terms of Service before signing up for online access. I don't remember the details, but I'd be surprised if they didn't include a clause saying that you're solely responsible for safeguarding your password. The one that they insist be of such low quality that it is easily cracked through brute-force methods.</p><br /><p><a href=\"http://www.lockdown.co.uk/?pg=combi\" rel=\"nofollow\">[www.lockdown.co.uk]</a></p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15587883, 'yagisencho')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584793\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=542811\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-542811-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=542811\">Raekwon</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584793\"><abbr class=\"published\" title=\"2009-09-24T18:04:00-05:00\">September 24, 2009  6:04 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584793);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584793');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>My bank (PSECU) has the same lame policies.  It was hard coming up with such a crappy password to protect my banking.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584793, 'Raekwon')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15584808\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=134363\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-134363-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=134363\">wagenejm</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15584808\"><abbr class=\"published\" title=\"2009-09-24T18:04:28-05:00\">September 24, 2009  6:04 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15584808);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15584808');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>6-8 characters, no special characters and not case-sensitive? That seems eerily like the password policy for a 30-year-old mainframe.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15584808, 'wagenejm')\">Reply</a></div>		<!-- if it's a top level category ' -->							<div class=\"num-replies\">1 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15589317\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=531211\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=531211\">b4k4</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15589317\"><abbr class=\"published\" title=\"2009-09-24T20:39:49-05:00\">September 24, 2009  8:39 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15589317);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15589317');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15584808\" rel=\"nofollow\">wagenejm</a>: Sounds about right. They're probably trying to support some legacy system that should've be sent to a landfill years ago</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15589317, 'b4k4')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15585067\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=60345\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-60345-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=60345\">Red_Eye</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585067\"><abbr class=\"published\" title=\"2009-09-24T18:12:38-05:00\">September 24, 2009  6:12 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585067);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585067');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Sometimes its not a matter of a lame policy but a lame Database backend. There are some Large systems out there with old policies simply because the password fields are 10 chars long or less and cant take all the odd duck characters. The cost of replacing one of these systems can be in the 8-9 digit range depending on the size of the organization.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585067, 'Red_Eye')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15585113\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=114659\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-114659-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=114659\">QuantumRiff</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585113\"><abbr class=\"published\" title=\"2009-09-24T18:14:02-05:00\">September 24, 2009  6:14 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585113);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585113');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>The no special characters is the fault of a kid named Little Bobby Tables.. <a href=\"http://xkcd.com/327/\" rel=\"nofollow\">[xkcd.com]</a></p><p>Funny, but also sad that its so true in big companies.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585113, 'QuantumRiff')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15585146\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">Jeff_McAwes0me    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585146\"><abbr class=\"published\" title=\"2009-09-24T18:15:14-05:00\">September 24, 2009  6:15 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585146);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585146');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>Ok computer nerds, accorting to my calculations, there are exactly 2.9017 Trillion possible passwords for AMEX (36^8+36^7+36^6, that's right, right?). How long would it take to crack using brute force?</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585146, 'Jeff_McAwes0me')\">Reply</a></div>		<!-- if it's a top level category ' -->													<div class=\"num-replies\">7 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15593199\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">rickn99    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15593199\"><abbr class=\"published\" title=\"2009-09-24T23:10:53-05:00\">September 24, 2009 11:10 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15593199);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15593199');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585146\" rel=\"nofollow\">Jeff_McAwes0me</a>: Either immediately or forever.  My account locks after 3 bad attempts.  Probably shouldn't have used 'aaaaaaaa', I guess.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15593199, 'rickn99')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment\" id=\"comment-15586034\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=436259\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-436259-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=436259\">MostlyHarmless</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15586034\"><abbr class=\"published\" title=\"2009-09-24T18:44:21-05:00\">September 24, 2009  6:44 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15586034);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15586034');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585146\" rel=\"nofollow\">Jeff_McAwes0me</a>: What johnva said.</p><p>Most savvy hackers use <a href=\"http://en.wikipedia.org/wiki/Rainbow_table\" rel=\"nofollow\">Rainbow Tables</a>. Makes thier life SOOO much easier.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15586034, 'MostlyHarmless')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment\" id=\"comment-15585689\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=929652\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-929652-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=929652\">katstermonster</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585689\"><abbr class=\"published\" title=\"2009-09-24T18:33:08-05:00\">September 24, 2009  6:33 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585689);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585689');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585146\" rel=\"nofollow\">Jeff_McAwes0me</a>: It actually makes a huge difference. You can write a fairly simple brute force hacker that can go through all those possibilities in...well, a few hours, maybe. Under a day, for sure. Granted, they probably have a \"3 tries\" limit or something, but I wouldn't be surprised if they didn't, given this disastrous policy. Also, the vast majority of people use real words for their passwords, so if you cheated and only went through those, it'd be even faster.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585689, 'katstermonster')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15587013\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=270824\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-270824-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=270824\">ThinkerTDM</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15587013\"><abbr class=\"published\" title=\"2009-09-24T19:18:59-05:00\">September 24, 2009  7:18 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15587013);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15587013');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"http://consumerist.com/5366403/american-express-wants-you-to-use-lame-passwords#c15585689\" rel=\"nofollow\">katstermonster</a>: I'm willing to bet that a company that has a password policy like AmEx probably is lacking on the other IT things for security.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15587013, 'ThinkerTDM')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15585279\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">Jeff_McAwes0me    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585279\"><abbr class=\"published\" title=\"2009-09-24T18:19:48-05:00\">September 24, 2009  6:19 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585279);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585279');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"http://consumerist.com/5366403/american-express-wants-you-to-use-lame-passwords#c15585146\" rel=\"nofollow\">Jeff_McAwes0me</a>: In fact, it is probably slightly less than that, since there can't be any passwords that are either all numbers or all letters. Stupid AMEX. It ends up being only 2.684 Trillion.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585279, 'Jeff_McAwes0me')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15585706\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=224192\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-224192-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=224192\">johnva</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585706\"><abbr class=\"published\" title=\"2009-09-24T18:33:39-05:00\">September 24, 2009  6:33 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585706);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585706');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585279\" rel=\"nofollow\">Jeff_McAwes0me</a>: Any reasonable search would not use brute force.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585706, 'johnva')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15585615\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1012446\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1012446\">Cant_stop_the_rock</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585615\"><abbr class=\"published\" title=\"2009-09-24T18:31:07-05:00\">September 24, 2009  6:31 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585615);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585615');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585279\" rel=\"nofollow\">Jeff_McAwes0me</a>: <br />If you could make 1000 attempts per second (keeping in mind this is a remote system you're accessing over HTTP), it would take an average of 41 years.  If you could make 100,000 attempts per second, someone would notice.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585615, 'Cant_stop_the_rock')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15586017\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">sqlrob    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15586017\"><abbr class=\"published\" title=\"2009-09-24T18:43:48-05:00\">September 24, 2009  6:43 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15586017);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15586017');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585615\" rel=\"nofollow\">Cant_stop_the_rock</a>: <br />Spread across a botnet, and you're talking a lot less than 41 years.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15586017, 'sqlrob')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15587843\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1012446\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1012446\">Cant_stop_the_rock</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15587843\"><abbr class=\"published\" title=\"2009-09-24T19:49:27-05:00\">September 24, 2009  7:49 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15587843);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15587843');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15586017\" rel=\"nofollow\">sqlrob</a>:</p><p>A random password would still take an average of 1.3 trillion attempts to find with a botnet, and I'm confident that American Expres would notice the 1.3 trillion failed login attempts on a single account.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15587843, 'Cant_stop_the_rock')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15595407\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=224192\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-224192-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=224192\">johnva</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15595407\"><abbr class=\"published\" title=\"2009-09-25T01:11:58-05:00\">September 25, 2009  1:11 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15595407);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15595407');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15587843\" rel=\"nofollow\">Cant_stop_the_rock</a>: Read and understand my post above about \"online\" vs. \"offline\" cracking.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15595407, 'johnva')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15585789\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=224192\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-224192-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=224192\">johnva</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585789\"><abbr class=\"published\" title=\"2009-09-24T18:36:24-05:00\">September 24, 2009  6:36 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585789);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585789');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585615\" rel=\"nofollow\">Cant_stop_the_rock</a>: You're assuming that it would be an online search. There's also the possibility of someone breaking into their systems, stealing their database of password hashes, and doing it offline.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585789, 'johnva')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15596826\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=108491\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=108491\">glorpy</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15596826\"><abbr class=\"published\" title=\"2009-09-25T02:34:49-05:00\">September 25, 2009  2:34 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15596826);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15596826');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585789\" rel=\"nofollow\">johnva</a>: No special characters and case-insensitive means they're likely directly accessing the mainframe without any offloaded pre-processing, which could convert the special characters into a friendly hash. No, the password is very likely stored plaintext. And a trivial DoS attack would simply throw the same password at every possible accountname from a slew of zombie machines. You'll almost certainly get a hit, and meanwhile, you'll prevent AmEx from actually doing real authentication.</p><p>All in all, AmEx really needs to resolve this problem - especially since it's not a huge IT investment to do pre-processing on the fields on an intermediary machine.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15596826, 'glorpy')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15585169\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1012446\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1012446\">Cant_stop_the_rock</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585169\"><abbr class=\"published\" title=\"2009-09-24T18:16:11-05:00\">September 24, 2009  6:16 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585169);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585169');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Before we assume that your password is susceptible to a brute force attack because there are only 2.9 trillion possible passwords, do we know what happens if you actually <i>attempt</i> a brute force attack?  I don't know about American Express, but some of my financial accounts will lock me out if I make a certain number of failed login attempts.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585169, 'Cant_stop_the_rock')\">Reply</a></div>		<!-- if it's a top level category ' -->									<div class=\"num-replies\">3 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15590740\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=131723\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-131723-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=131723\">theblackdog</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15590740\"><abbr class=\"published\" title=\"2009-09-24T21:26:18-05:00\">September 24, 2009  9:26 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15590740);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15590740');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585169\" rel=\"nofollow\">Cant_stop_the_rock</a>: Yeah, Amex only allows 3 attempts before lockout</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15590740, 'theblackdog')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15591912\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=363287\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-363287-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=363287\">legwork</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15591912\"><abbr class=\"published\" title=\"2009-09-24T22:13:29-05:00\">September 24, 2009 10:13 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15591912);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15591912');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585169\" rel=\"nofollow\">Cant_stop_the_rock</a>: I'll bite. Who made the rule that attacks can only be made via their web interface?</p><p>Sounds like a child's \"monster\" rule, where we're safe so long as our arms don't hang off the bed.</p><p>Lazy people are a thief's best ally.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15591912, 'legwork')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15587050\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=270824\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-270824-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=270824\">ThinkerTDM</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15587050\"><abbr class=\"published\" title=\"2009-09-24T19:20:14-05:00\">September 24, 2009  7:20 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15587050);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15587050');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"http://consumerist.com/5366403/american-express-wants-you-to-use-lame-passwords#c15585169\" rel=\"nofollow\">Cant_stop_the_rock</a>: You're right- Maybe they spent all their money on other security procedures, rather than password strength. Then again, they probably don't give a shit about computer security.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15587050, 'ThinkerTDM')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15585261\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">knyghtryda    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585261\"><abbr class=\"published\" title=\"2009-09-24T18:19:10-05:00\">September 24, 2009  6:19 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585261);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585261');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>you know what is even worse than this?  Banks that make you use a 4 number pin.  My Wells Fargo account allows a pin of any length, but Wamu (excuse me... chase) and Citi both only allow 4 number pins.  That's far worse than a 6-8 character password.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585261, 'knyghtryda')\">Reply</a></div>		<!-- if it's a top level category ' -->											<div class=\"num-replies\">5 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15592308\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=352646\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-352646-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=352646\">nybiker</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15592308\"><abbr class=\"published\" title=\"2009-09-24T22:30:37-05:00\">September 24, 2009 10:30 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15592308);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15592308');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15585261\" rel=\"nofollow\">knyghtryda</a>: My citibank pin is 6 digits.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15592308, 'nybiker')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15594881\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=281834\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=281834\">Coelacanth</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15594881\"><abbr class=\"published\" title=\"2009-09-25T00:40:25-05:00\">September 25, 2009 12:40 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15594881);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15594881');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"http://consumerist.com/5366403/american-express-wants-you-to-use-lame-passwords#c15592308\" rel=\"nofollow\">nybiker</a>: Why wouldn't the online account access be any different and not lock an account after a few failed attempts?</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15594881, 'Coelacanth')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15585369\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">Jeff_McAwes0me    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585369\"><abbr class=\"published\" title=\"2009-09-24T18:22:37-05:00\">September 24, 2009  6:22 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585369);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585369');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"http://consumerist.com/5366403/american-express-wants-you-to-use-lame-passwords#c15585261\" rel=\"nofollow\">knyghtryda</a>: Yes, but you also have to physically posess the card (unless you are referring to an internet account password, in which case... yikes). Also, I would think an ATM would eventually stop you after you try 0000, 0001, 0002... etc.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585369, 'Jeff_McAwes0me')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15595123\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=140241\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=140241\">XTC46</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15595123\"><abbr class=\"published\" title=\"2009-09-25T00:53:31-05:00\">September 25, 2009 12:53 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15595123);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15595123');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15585369\" rel=\"nofollow\">Jeff_McAwes0me</a>: My Bank's atm will actually keep the card if you type the pin wrong 5 times.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15595123, 'XTC46')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15585518\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=738213\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-738213-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=738213\">JGKojak</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585518\"><abbr class=\"published\" title=\"2009-09-24T18:27:44-05:00\">September 24, 2009  6:27 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585518);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585518');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"http://consumerist.com/5366403/american-express-wants-you-to-use-lame-passwords#c15585369\" rel=\"nofollow\">Jeff_McAwes0me</a>: <br />You would THINK it would, wouldn't you?</p><br /><p>I had a friend randomly assigned some obvious pin (0001) and the bank gave him a hard time when he wanted to change it.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585518, 'JGKojak')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15585431\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=138228\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=138228\">McFister</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585431\"><abbr class=\"published\" title=\"2009-09-24T18:24:54-05:00\">September 24, 2009  6:24 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585431);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585431');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>It's particularly irritating if you are auto-generating random passwords.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585431, 'McFister')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15585487\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=738213\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-738213-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=738213\">JGKojak</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585487\"><abbr class=\"published\" title=\"2009-09-24T18:26:35-05:00\">September 24, 2009  6:26 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585487);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585487');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>The point is that this goes against established IT procedure.</p><br /><p>This is what happens when overpaid executives who don't understand tech have to negotiate with underpaid IT contractors- that security scheme is a big F.U.-U-get-whut-u-payfor from whoever their department or contractor is- because they know the exec don't understand to ask for more.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585487, 'JGKojak')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","","","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15585709\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=970156\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=970156\">ubermex</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585709\"><abbr class=\"published\" title=\"2009-09-24T18:33:44-05:00\">September 24, 2009  6:33 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585709);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585709');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I hate password requirements of ANY kind. Excessive requirements end up causing me to make simple passwords out of frustration.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585709, 'ubermex')\">Reply</a></div>		<!-- if it's a top level category ' -->									<div class=\"num-replies\">3 replies</div>	    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->     <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment\" id=\"comment-15585934\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">knyghtryda    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585934\"><abbr class=\"published\" title=\"2009-09-24T18:41:01-05:00\">September 24, 2009  6:41 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585934);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585934');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585709\" rel=\"nofollow\">ubermex</a>:</p><p>There definitely needs to be some kind of minimum password requirement though.  I agree that overly stringent password requirements just make users hate their passwords, but a 4 character password that's a common word isn't gonna be much better.  I say stick with a minimum length (8 characters is a good minimum) and a number/special character requirement.  Leave the rest to the user's discretion.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585934, 'knyghtryda')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15586813\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1504\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-1504-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1504\">RandomHookup</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15586813\"><abbr class=\"published\" title=\"2009-09-24T19:11:30-05:00\">September 24, 2009  7:11 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15586813);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15586813');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15585934\" rel=\"nofollow\">knyghtryda</a>: I get especially irritated at sites that aren't anything special and that I'm only giving a name and an email address, yet ask you to give a complicated password (and even better don't tell you before you input it). I have a low end password that appears to be random letters. For most of these sites, I don't care as the damage to be done is minimal.</p><br /><p>I also find it funny that the password gods decide my choice is much more secure if I add a 1 to the end of my random letters.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15586813, 'RandomHookup')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- Loop through the reply comments -->        <div class=\"reply-container\" >            <div class=\"comment last\" id=\"comment-15595207\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=140241\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=140241\">XTC46</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15595207\"><abbr class=\"published\" title=\"2009-09-25T00:58:36-05:00\">September 25, 2009 12:58 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15595207);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15595207');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>@<a href=\"#c15586813\" rel=\"nofollow\">RandomHookup</a>: adding that 1 does make it more secure, not only does it add an extra character, but it adds another kind of character. use the following as an example.</p><br /><p>password - 8 characters, all one kind of character, can be found in a dictionary, so it s very easy (and fast to crack)<br />Password - a bit more difficult than the above becasue now the cracker has exponentially increased the number of possibilites since now upper and lower case letters have to be taken into consideration<br />Password1 - Even more difficult becasue now the password is even longer, and includes 3 kinds of characters, (uppercase letters, lower case letters, and numbers) and this would meet most basic complexity requirements.</p><br /><p>So to you, it looks pretty much the same, no big deal. To a computer trying to crack it, its significantly more work.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15595207, 'XTC46')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>     <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	     <!-- Loop through the reply comments -->                    <div class=\"comment last\" id=\"comment-15585910\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=224192\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-224192-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=224192\">johnva</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15585910\"><abbr class=\"published\" title=\"2009-09-24T18:40:21-05:00\">September 24, 2009  6:40 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15585910);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15585910');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>@<a href=\"#c15585709\" rel=\"nofollow\">ubermex</a>: That's always a danger, but what should be done when half of people will pick their birthday or their kid's name without restrictions? There's no great solution yet, but at least it's recognized now that the usability concerns are important to the actual security of password schemes.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15585910, 'johnva')\">Reply</a></div>		 	    </div><!-- end reply- button -->    </div></div>                <!-- Display comment (reply comment, which may be a parent of more replies) -->            <div class=\"inner-reply-container\" >                 <!-- For each reply comment, recursively display any reply comments -->          	    </div>        	</div>    </div>","","","","","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15586452\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=887707\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-887707-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=887707\">Skaperen</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15586452\"><abbr class=\"published\" title=\"2009-09-24T18:59:22-05:00\">September 24, 2009  6:59 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15586452);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15586452');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Having worked with computers that involve users who have passwords for over 30 years, I've learned plenty on user behavior with regard to passwords.  While it is the case that the simpler password is easier to crack, the more complex passwords can actually be more vulnerable.  How is this?  Such passwords are generally hard to remember.  So people write them down and stick them somewhere that turns out to be a common place to find passwords, and generally very near the computer (even at home).  Adding in digits and special characters to a password someone can remember may be the thing that makes them forget.  They forget which special character they added, and where.</p><p>The advice I give to people is to think of a phrase they figure is important (the longer the better, but at least 6 words).  Use the first letter of each word.  For the key words in the phrase, capitalize the letters for those.  My archive master password is well over 20 characters, looks like a jumble to anyone that might see it, but is easy for me to remember despite never having written it down.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15586452, 'Skaperen')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15587327\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=349910\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=349910\">nucwin83</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15587327\"><abbr class=\"published\" title=\"2009-09-24T19:31:27-05:00\">September 24, 2009  7:31 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15587327);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15587327');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Apple's Juniper (now Barclay) card has the same types of restrictions.  I've never been told my password was too long until I signed up for that website.  Oh well.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15587327, 'nucwin83')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","","","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15589706\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=22998\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-22998-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=22998\">axiomatic</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15589706\"><abbr class=\"published\" title=\"2009-09-24T20:52:35-05:00\">September 24, 2009  8:52 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15589706);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15589706');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Heres the deal people. There are technical reasons in the background that your password needs to be more than 8 characters. They really need to be more than 16 character actually.</p><p>In most (not all) systems the password storing tool used to encrypt the passwords was some variation of something called (LM HASH) (<a href=\"http://en.wikipedia.org/wiki/LM_hash\" rel=\"nofollow\">[en.wikipedia.org]</a>).</p><p>Most of the hacker tools used for cracking passwords was based on cracking LM HASH. Hacker tools like \"l0pht\" and others were quite good at cracking LM HASH. Someones earlier example in this thread suggested how a password of \"AMEX\" or some combination of AMEX like \"MAXE\" would be to crack. Unfortunately it would only take l0pht about 30 to 40 minutes to crack. So anytime you see a new requirement of \"more than 16 characters, and must contain a capital letter and a special character\" are companies that have implemented a password system STRONGER than the weak LM HASH.</p><p>Now enter the world of GPGPU's (using your video cards microprocessor as a General Purpose GPU) what used to take a regualr Intel CPU 30 to 40 minutes to crack \"MAXE\" now unfortunately takes about 5 minutes using a GPGPU.</p><p>So word to the wise. Stop complaining about those long passwords. I tried to put this post in laymans terms so everyone could follow what I am saying, but trust me. An 8 character password that has only lower case passwords is TRIVIAL to crack with the tools the \"script kiddies\" have available to them today.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15589706, 'axiomatic')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15590273\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1225391\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-1225391-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1225391\">Waiting for the next Ren Fest</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15590273\"><abbr class=\"published\" title=\"2009-09-24T21:10:01-05:00\">September 24, 2009  9:10 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15590273);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15590273');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I despise all the different password requirements. Since 98%* of all of all break ins are by either:</p><p>A) Someone who has hacked into their system and stolen the whole database (most common)<br />or<br />B) Social engineering (I'll give you this $5 Starbux card for your password or they look under your keyboard for a post it note)</p><p>It does not matter how strong or weak your password is at that point. It does not matter if your password is \"Password\" or \"gte*4Dr3@Z8?\", once they have stolen the main database, or found the postit note under your keyboard, you are done for.</p><p>Just let me use whatever password I want (OK, rule out Password, my name, etc), and keep your freaking systems secure.</p><p>*This is a made up statistic, but I will wager a HardCore Cider that the actual number of breeches from those is higher than that.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15590273, 'Waiting for the next Ren Fest')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15591138\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=535937\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=535937\">dwasifar</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15591138\"><abbr class=\"published\" title=\"2009-09-24T21:41:13-05:00\">September 24, 2009  9:41 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15591138);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15591138');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>I used to work for a major bank (which I shall not name here) and I was always frustrated by the password requirements for the internal systems: Must be exactly eight characters, must contain at least one number not at the beginning or end, may not contain any of a huge number of dictionary words.  With every such restriction, you knock huge groups of potential passwords out of the range of possible options, and make a brute-force attack easier to achieve.  It really irked me but there was nothing I could do about it.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15591138, 'dwasifar')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15592345\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=352646\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-352646-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=352646\">nybiker</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15592345\"><abbr class=\"published\" title=\"2009-09-24T22:32:14-05:00\">September 24, 2009 10:32 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15592345);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15592345');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>Let's also remember that you need to know not only the password, but my account's username to get in.  I am guessing that the password is of no use if you don't know the username to which it belongs.<br /><br />Or am I missing something?</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15592345, 'nybiker')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15594048\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1276337\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1276337\">slulplal</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15594048\"><abbr class=\"published\" title=\"2009-09-24T23:54:14-05:00\">September 24, 2009 11:54 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15594048);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15594048');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Not only are they behind on passwords, but their entire database/field limitations.  their street address field only allows 20 characters.  I have to remove all of the vowels from my street address just to fit it.  This also makes it so that I can't use my card on the websites that do checks on exact street address names for billing address.  I have to remember to devowel my address just to place an order.  I will get the message once and switch to my Visa.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15594048, 'slulplal')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15594927\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=281834\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=281834\">Coelacanth</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15594927\"><abbr class=\"published\" title=\"2009-09-25T00:43:12-05:00\">September 25, 2009 12:43 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15594927);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15594927');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p><p>While not the strongest, or recent \"best practices,\" but having a 6-8 character password does allow somebody to have a relatively strong level of protection.</p><br /><p>I would also venture to guess that after a limited number of failed login attempts, the account would be locked.</p><br /><p>Also, alphanumeric passwords avoid the possibility of SQL-injection or other variants.</p><br /><p>Not terribly worried here.</p></p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15594927, 'Coelacanth')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","","","","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15599982\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">robo_geek    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15599982\"><abbr class=\"published\" title=\"2009-09-25T07:32:23-05:00\">September 25, 2009  7:32 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15599982);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15599982');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>The lack of special characters does not make the front-end a whole lot weaker, because their authentication service is going to lock the user account after three tries, so the other 14 billion brute force attempts will be all in vain.</p><p>You could create a script to try only twice, end the session, try another two times, but the catch is that you can also have to create your own login id, which is something you cannot brute force.</p><p>The bigger concern is that the lack of special characters tells me that it's a simple database behind the scenes storing your password, as any of the more sophisticated authentication front ends for web apps (e.g. RSA ClearTrust) allow you to use a good password.</p><p>Simple databases behind web applications are frequent attack targets.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15599982, 'robo_geek')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15600677\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=248414\"><img        src=\"http://consumerist.com/assets_c/userpics/userpic-248414-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=248414\">David in Brasil</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15600677\"><abbr class=\"published\" title=\"2009-09-25T10:04:14-05:00\">September 25, 2009 10:04 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15600677);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15600677');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Slightly off topic, but my favorite Amex security rant:  My company accepted Amex as a source of payment several years ago.  Then we found that one of my partners was a crook; we forced him out and he set up a competing company.  He diverted all of our Amex correspondence to his new company, but our name was still on the account.  I called Amex to cancel our merchant agreement, but they told me that only the person who originally set the account up could do that.  I explained to them that this person was now a competitor, had a history of fraud, had access to our account and I was afraid of some type of shenanigans that he could pull just to make life miserable for us.  \"Too bad\", they said, and refused to make any changes to our account. I called their loss prevention department, their identity theft dept., and their customer service dept. and always got the same answer.</p><p>I decided then and there that Amex only gives lip service to identity theft.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15600677, 'David in Brasil')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15601163\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=1019789\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=1019789\">Racshot65</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15601163\"><abbr class=\"published\" title=\"2009-09-25T11:45:18-05:00\">September 25, 2009 11:45 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15601163);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15601163');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Password limitations like this were discussed on an episode of Security Now a while ago. Someone from a bank wrote in and said it was because the back end systems are so old that's all they support.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15601163, 'Racshot65')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15601595\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=267279\"><img        src=\"/mt-static/support/assets_c/userpics/userpic-267279-100x100.png\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=267279\">chiieddy</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15601595\"><abbr class=\"published\" title=\"2009-09-25T12:47:28-05:00\">September 25, 2009 12:47 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15601595);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15601595');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>AmEx isn't the only one.  I've recently begun redoing my passwords in KeepPass and have been surprised on the lax security on some financial and other sites that have personal information (insurance, etc):</p><p>Citizens Bank - No Symbols, spaces<br />ING Direct - Only 4 numbers <br />Emigrant Direct - No Symbols, spaces<br />Chase - No Symbols, spaces<br />Discover - no Symbols, spaces<br />Comcast - no Symbols, spaces<br />ADP - limited symbols, no spaces</p><p>The vast majority of sites requires 6 - 8 characters, and I'm extremely happy when I can randomly generate 10 random ANSI characters.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15601595, 'chiieddy')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15602490\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=144504\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=144504\">uffa</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15602490\"><abbr class=\"published\" title=\"2009-09-25T13:47:38-05:00\">September 25, 2009  1:47 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15602490);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15602490');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>A few years back, Amex had different password policies. My password at the time did contain special characters and then one day I couldn't login. I knew the password was right because I used the same one on another cc site. I had to reset it and it was then that I was presented with the restrictions they have today. Strange that they would go backward like that.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15602490, 'uffa')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","<div class=\"comments-content\">        <div class=\"comment\" id=\"comment-15612075\">    <div class=\"inner\">	 <div class=\"user-pic\">        <a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;amp;blog_id=1&amp;amp;id=542046\"><img        src=\"/css/images/default.gif\"        width=\"60\" height=\"60\" alt=\"user-pic\" /></a>    </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\"><a href=\"http://consumerist.com/cgi-bin/mt/mt-cp.cgi?__mode=view&amp;blog_id=1&amp;id=542046\">fdbryant3</a>        </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15612075\"><abbr class=\"published\" title=\"2009-09-25T18:58:56-05:00\">September 25, 2009  6:58 PM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15612075);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15612075');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Yeah lots of banks and other financial institutions have a problem with this. The problem is that the financial sector were using mainframe networks long before the advent of the commercial Internet back in a time when these rules were sufficient and more complex rule were impractical and unnecessary. The problem is they are still operating on these old program and cannot handle more complex passwords.</p><p>My guess is the problem with upgrading besides the time and money involved is the systems probably has to do with being able to interface with other global institutions which may or may not be able to upgrade.</p><p>Eh - you can still construct a fairly secure password under those rules. The one I use is rated strong at PasswordMeter and with a couple of tweaks I can get it up to very strong. The hard part is creating one that is easily memorable. That is why I use Roboform and I'm considering LastPass.</p><p>To be honest while it is important to implement a strong password policy - the fact is most security breaches occur not by cracking the password, but by simply getting people to give up their password.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15612075, 'fdbryant3')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>","","<div class=\"comments-content\">        <div class=\"comment last\" id=\"comment-15635274\">    <div class=\"inner\">	 <div class=\"user-pic\">                <a href=\"\"><img src=\"/css/images/default.gif\"         width=\"60\" height=\"60\" alt=\"user-pic\" /></a>            </div>        <div class=\"comment-header\">            <div class=\"asset-meta\"> <div class=\"vcard author\">tekdemon    </div>				<div class=\"comment-date\"><a href=\"http://consumerist.com/2009/09/american-express-wants-you-to-use-lame-passwords.html#comment-15635274\"><abbr class=\"published\" title=\"2009-09-27T11:10:48-05:00\">September 27, 2009 11:10 AM</abbr></a></div>				<div class=\"comment-moderate\"><span><a href=\"javascript:moderateComment(15635274);\">Moderate</a> |</span><a href='javascript:void(0)' onClick=\"return moderate(this, 'http://consumerist.com/cgi-bin/mt/plugins/Moderate/moderate.cgi?__mode=flag&comment_id=15635274');\">Flag for review</a></div>            </div>        </div><!-- end comment header -->        <div class=\"comment-content\">            <p>Far as I can tell having access to your account password mostly means that whoever stole it could pay your bill for you.  It's not the same as your bank where you have accounts that actually hold money, and they can't use the card just from having your online account password so I suspect they haven't changed the password policy because this way it's convenient.<br />And I for one am going to go against the grain and say that I don't want the Amex login to be as difficult as those of other places.<br />Amex happens to have pretty damned good algorithms for spotting when a purchase isn't yours, and stealing your online account information is pretty worthless for Amex's website so I hope they ignore any idiotic e-mails demanding 90 character passwords.</p>        </div>	<div class=\"reply\">	 <div class=\"reply-button\"><a title=\"Reply\" href=\"javascript:void(0);\" onclick=\"mtReplyCommentOnClick(15635274, 'tekdemon')\">Reply</a></div>		<!-- if it's a top level category ' -->		    </div><!-- end reply- button -->    </div></div>        <!-- Display comment (top level parent) -->    </div>");


