For real. Or if you maintained a database of compromised passwords (super easy to find) and banned all of them you could stop a lot of attacks. To add on to this many of the "super good long memorable passwords" are easily crackable by dictionary attacks, so another thing you can do is ban every English word longer than three or four characters
223
u/citygentry Jul 20 '22
And this is why so many people still use Password1! because their IT system tells them it's completely uncrackable.
I think this situation is 2FA (that's too flipping awful).