We're adding additional requirements to all future passwords to maintain a high standard of security when accessing the platform.
Users will need to incorporate these new requirements that we deem best practice, to reduce the liklihood and impact of any malicious intervention.
All existing passwords that have already been set will not change.
1. Must be between 8 and 64 characters
2. Must have at least 3 of the following:
a lowercase letter
an uppercase letter
a digit
a symbol
3. NEW:
Must not match a known breached (common) password
Full list here, please don't share list externally as some are explicit
Also includes: "Password1*" and "Password1!" - sorry guys!!!
4. NEW:
Must not contain parts of the username/email
Your name or company name cannot be used as your password.
For example, for this user: [email protected]
These password are not allowed:
john.Smith123
12John.smith3
company123
@companyXYZ
Attempting an invalid password (from rules #3 or #4) will provide the following warning: