It seems like each website has it's own password standards.
Some want 5 letters, some want a minimum of 10, some want a maximum of 8, some want a number, some want a mix of capital and lower case letters, some want an underscore, some want a special character @#$%@#@%@#%...others don't allow special characters etc.
Obviously there is absolutely no need for something that restrictive. All it does, is that people are stuck using uncommon passwords...which in turn means that they end up writing them down or constantly forgetting them, which bypasses the security.
So how about we create a common set of password standards...one that doesn't force the user to deviate from their common passwords, yet one that does the bare minimum to make brute forcing it with bots complicated.
My password has been letters + numbers at the end for a long time and I know it's secure because it's not a common word or numbers that have to do with me. No capitals, no punctuations, only lowercase letters and numbers. When a website forces me to use other letters in my password, I keep forgetting it and I am forced to use "Lost my password" all the time, which makes me want to use that service less and less.
Were you inspired to post this by today's XKCD comic? Link : http://xkcd.com/936/