This paper analyses password policies from different institutions,
companies and websites. Some of these policies are
presented as a set of guidelines or advice, and not as mandatory
rules. We have also compared the password requirements
of prominent authentication assurance frameworks.
Password policies vary in many ways. There were similarities
and differences in the requirements of the policies we
examined. However, we have not found consistent password
policy requirements. It is noticeable that large commercial
websites such as yahoo or eBay have lax password policies
that are only partially enforced. Some websites go as far as to
enforce only the length rule while permitting passwords such
as ”123456” even though it specifically states in its policy that
this is a bad password. Examining the four national/regional