I reset online passwords regularly (as should everyone). And I approve of password restrictions (minimum lengths, no reuse, at least one digit and one uppercase, etc.). But, as you can see in this validation screen, American Express apparently does not want passwords to be *too* secure! FAIL!
http://www.pcmag.com/article2/0,2817,2358985,00.as...
From the article:
"We discourage the use of special characters because hacking softwares can recognize them very easily.
The length of the password is limited to 8 characters to reduce keyboard contact. Some softwares can decipher a password based on the information of "most common keys pressed".
Therefore, lesser keys punched in a given frame of time lessen the possibility of the password being cracked."
Who knew? I've since changed all my passwords to 'qwerty'!
(Article: The government has all the keys ... summary title). The gov't keys really doesn't matter, banks scan for odd activity and report anyway!