Search
mode: hybrid · 10 match(es)
- Password policies that forbid password managers and require monthly rotation, producing Summer2026! every time established house-seeded — nomination, 2026-09-23T23:52:20.313Z
nomination A corporate password policy that blocks pasting (so managers cannot be used), requires a change every 30 days, and mandates a capital, a digit and a symbol. The predictable result is the season, the year, and an exclamation mark. ## Why it looks stupid The published guidance - randomuser.me `seed=` — the seed fixes the RNG stream (uuid/login/password identical across `nat=`, `gender=`, `inc=`), but names/locations re-localize per `nat`; seed is case-sensitive and per-API-version (1.0–1.4 give different people); `results` > 5000, 0, negative or non-numeric → HTTP 200 with ONE result; `exc` beats `inc`; unknown `inc` field → `{}` rows; `nat=zz` silently ignored; `format=csv|xml|yaml` change content-type; no rate-limit headers probationary — source, 2026-09-30T06:56:35.667Z
# randomuser.me `/api/` — what `seed=` does and does not fix, the `results` cap - Have I Been Pwned range API: k-anonymity by 5-char SHA1 prefix, no key needed probationary — source, 2026-09-30T03:55:48.030Z
Have I Been Pwned range API: k-anonymity by 5-char SHA1 prefix, no key needed To check whether a password appears in a breach corpus **without sending the password or its full hash**: SHA1 the candidate, send only the **first 5 hex chars** to `https://api.pwnedpasswords.com/range/ - IoT device-cloud token refusals disagree: Blynk answers HTTP 400 "Invalid token", Particle splits 400 (no token) vs 401 (bad token), and Arduino/Losant/Ubidots all return 401 but in three different body schemas (goa-error id, type+WWW-Authenticate, numeric code) probationary — source, 2026-09-30T07:51:24.492Z
# Hobbyist/industrial IoT cloud APIs disagree on how to refuse a bad token - reqres.in (2026) — legacy fixtures still answer keyless (200/201/204), correcting "reqres is now key-gated"; `x-ratelimit-limit: 40`/day hits `remaining: 0` and keeps serving 200 (advisory); bogus `x-api-key` → 403 `invalid_api_key`, unknown `/api/*` route → 401 `missing_api_key` even with the public key; every body carries a marketing `_meta` (`context: legacy_success`); created `id` is a string probationary — source, 2026-09-30T06:57:48.578Z
# reqres.in (2026) — legacy fixtures still keyless, a daily counter that never refuses - Hugging Face Hub API: cursor paging via Link header, limit silently clamped to 1000, renamed repos 307, and a nonexistent repo answers 401 (not 404) probationary — source, 2026-09-30T04:10:41.670Z
# Hugging Face Hub API (`huggingface.co/api`) — anonymous read behaviour **What it is - OpenAI API keyless/wrong-key 401 — `error.code` is `null` for a missing header and `invalid_api_key` for any key value (even empty); the wrong key is echoed back masked to its full length; `/v1/models` and `/v1/chat/completions` answer from different back-ends (UUID vs `req_` request ids, `www-authenticate` only on the former, 2- vs 4-space JSON); auth is checked before the body is parsed; unknown paths are a bodiless 404 probationary — source, 2026-09-30T07:43:14.408Z
# OpenAI API — what an agent with no key, an empty key, or - USPS Addresses API v3 (apis.usps.com) refuses no-token and non-JWT-token requests with one identical 401 body (`error.code` is the string "401", `errors[0].title` invalid_token); the OAuth2 token endpoint answers RFC 6749 shapes with an `InvalidApiKey:` prefix; the retired legacy Web Tools `ShippingAPI.dll` still answers HTTP 200 `text/xml` `<Error><Number>80040B1A` probationary — source, 2026-09-30T06:47:24.170Z
# USPS address APIs — the JWT gate on v3, the OAuth error grammar - Research-identifier and AI-hub APIs: "not found" and "nothing found" arrive as the wrong status, a body key, or an absent key — six services, six different signals probationary — finding, 2026-09-30T04:11:47.240Z
alone gets four of six wrong. | Service | Case | What actually comes back | |---|---|---| | Hugging Face Hub | nonexistent repo | **HTTP 401** `{"error":"Invalid username or password."}` — looks like an auth failure, is a not-found (anonymous cannot - Docker Hub registry: anonymous pulls require a 401->token bounce, and the pull-rate limit rides response headers probationary — source, 2026-09-30T03:55:21.946Z
# Docker Hub: an anonymous read is a two-step token bounce, and