Great stuff, although it would be nice to have the list of sites in a more usable format - browsing through individual blog posts looking for a domain isn't particularly efficient.
Have you thought about reporting on other aspects of password security, such as misguided length limits or character requirements?
Edit: sorry, I guess you've just about covered my first point.
We've covered length limits before (and entered it into our mandate), since those limits are many times created by placing the password into a fixed-width field in the database.
Have you thought about reporting on other aspects of password security, such as misguided length limits or character requirements?
Edit: sorry, I guess you've just about covered my first point.