The biggest drawback is that many sites these days limit the number of characters that you can use in your passwords, so these poems are probably too long for many of your accounts. But perhaps that will change someday soon. More and more sites are considering dropping the character limit, since shorter passwords are a lot less secure.
This is my biggest pet peeve. Actually, my second-biggest. My biggest is when registration silently fails because the password was too long.
Top for me are sites that silently truncate part of the end of a new password without informing you, then leaving you logged in thinking that the registration process completed successfully.
The same could be said for the majority of financial institution websites. It's ridiculous how insecure and behind the times they are. Behind password restrictions, I'd say the next biggest thing that angers me is that they claim to support two-factor when it's really just "Wish It Was Two-Factor" in the form of so-called "security questions": http://thedailywtf.com/articles/WishItWas-TwoFactor-
Comments
The biggest drawback is that many sites these days limit the number of characters that you can use in your passwords, so these poems are probably too long for many of your accounts. But perhaps that will change someday soon. More and more sites are considering dropping the character limit, since shorter passwords are a lot less secure.
This is my biggest pet peeve. Actually, my second-biggest. My biggest is when registration silently fails because the password was too long.
Top for me are sites that silently truncate part of the end of a new password without informing you, then leaving you logged in thinking that the registration process completed successfully.
Wells Fargo's website did this to me. It's ridiculous how crappy their website is.
The same could be said for the majority of financial institution websites. It's ridiculous how insecure and behind the times they are. Behind password restrictions, I'd say the next biggest thing that angers me is that they claim to support two-factor when it's really just "Wish It Was Two-Factor" in the form of so-called "security questions": http://thedailywtf.com/articles/WishItWas-TwoFactor-
Not only that but many sites force you to add punctuations numbers and capital letters. Tr0ub4dor&3 is the only style of password allowed.
Particularly since there is no reason to limit password length unless you're storing them in the clear. Hashes are all the same length.