We're adding additional requirements to all future passwords to maintain a high standard of security when accessing the platform.
Users will need to incorporate these new requirements that we deem best practice, to reduce the liklihood and impact of any malicious intervention.
All existing passwords that have already been set will not change.
1. Must be between 8 and 64 characters
2. Must have at least 3 of the following:
a lowercase letter
an uppercase letter
a digit
a symbol
3. Must not match a known breached (common) password
Password reuse is extremely common and puts your accounts at risk. When credentials are exposed in data breaches, attackers can use these known email and password combinations to access your other accounts. NIST guidelines specifically recommend checking user passwords against previously breached datasets.
This includes common favourites such as: "Password1*" and "Password1!"
4. Must not contain parts of the username/email
Your name or company name cannot be used as your password.
For example, for this user: [email protected]
These password are not allowed:
john.Smith123
12John.smith3
company123
@companyXYZ
Attempting an invalid password (from rules #3 or #4) will provide the following warning: