Context is that I had to register for a lot of accounts recently and some of the rules really make no sense.
Not name-and-shaming, but the best one I’ve seen recently is I might have accidentally performed an XSS attack on a career portal using a 40-digit randomly generated password…
It happens a bit too often that I make an account somewhere with a long, generated password and then when I log in it throws errors at me.
But a few times a website didn’t just show me an error, I got the whole crash dump including their encryption approach and versioning