Update: American Express has silently updated their authentication system. While the new criteria for passwords is an improvement, it is still far from perfect:
Must be different from your User ID
Must contain 8 to 20 characters, including one letter and number
May include the following characters: %,&, _, ?, #, =, -
Your new password cannot have any spaces and will not be case sensitive.

Update: American Express has silently updated their authentication system. While the new criteria for passwords is an improvement, it is still far from perfect:

  • Must be different from your User ID
  • Must contain 8 to 20 characters, including one letter and number
  • May include the following characters: %,&, _, ?, #, =, -
  • Your new password cannot have any spaces and will not be case sensitive.

315 notes

  1. free-bets reblogged this from ataferner
  2. passturd reblogged this from ataferner and added:
    I’m not really sure where...begin with this Customer “Support” email that Twice Refried...
  3. kennethlove reblogged this from enlavin and added:
    So that’s where I’ve been going wrong! I haven’t been using enough alphabets in my passwords. enlavin:
  4. supafamous reblogged this from ataferner
  5. ryanthejenks reblogged this from ataferner and added:
    Are you kidding me? Where did this guy learn about online security?!
  6. webmarc reblogged this from marco and added:
    While few things in life are ever complete, this does fall into the category of complete BS. Taken
  7. cowsandmilk reblogged this from marco and added:
    I’ll skip out on commenting on the American Express response, but the idea that you can’t have an 8 character...
  8. reidgober reblogged this from marco
  9. lkm reblogged this from ataferner and added:
    human: “I’m high as a kite.” Seriously. None of this makes...sense. Copious amounts of...
  10. toldorknown reblogged this from marco and added:
    It’s a crock. As I’m sure you know, encrypted characters are all equally easy to decrypt, which is to say virtually...
  11. neatso reblogged this from marco and added:
    Always wondered this myself. It seems...a weak security measure for a major financial...