Stronger, simpler password rules
Password requirements now focus on length instead of forced character classes (uppercase, number, special character) - a 8-character minimum replaces the old checklist. This follows current security guidance (NIST), since character-class rules tend to push people toward predictable rather than genuinely strong passwords.
We also check new and changed passwords against known data breaches - without your password ever leaving our systems in plaintext.
Existing passwords remain valid; the new rule applies to new and changed passwords going forward.