Multiple studies have shown that password complexity rules are counter-productive.
In fact, the scheme you're using is called out in one study as one of the weakest at providing real password protection.
If you really want to provide protection, allow us to use two-factor auth; as it is, the password complexity rules are just frustrating to the end-user.
In fact, the scheme you're using is called out in one study as one of the weakest at providing real password protection.
If you really want to provide protection, allow us to use two-factor auth; as it is, the password complexity rules are just frustrating to the end-user.