Top for me are sites that silently truncate part of the end of a new password without informing you, then leaving you logged in thinking that the registration process completed successfully.
The same could be said for the majority of financial institution websites. It's ridiculous how insecure and behind the times they are. Behind password restrictions, I'd say the next biggest thing that angers me is that they claim to support two-factor when it's really just "Wish It Was Two-Factor" in the form of so-called "security questions": http://thedailywtf.com/articles/WishItWas-TwoFactor-
Comments
Top for me are sites that silently truncate part of the end of a new password without informing you, then leaving you logged in thinking that the registration process completed successfully.
Wells Fargo's website did this to me. It's ridiculous how crappy their website is.
The same could be said for the majority of financial institution websites. It's ridiculous how insecure and behind the times they are. Behind password restrictions, I'd say the next biggest thing that angers me is that they claim to support two-factor when it's really just "Wish It Was Two-Factor" in the form of so-called "security questions": http://thedailywtf.com/articles/WishItWas-TwoFactor-