Ticketfly
No more than 20 characters in password.

seen from United States
seen from Colombia
seen from United States
seen from Venezuela
seen from United States

seen from United States
seen from United States
seen from India
seen from United States
seen from Malaysia
seen from United States
seen from United States
seen from United States
seen from United States

seen from Chile
seen from United Kingdom

seen from Malaysia

seen from United States
seen from United States

seen from United States
Ticketfly
No more than 20 characters in password.
Do they tell you what characters are and are not allowed? Haha, no.
Cool, I’ll just sit and guess till I get lucky.
The fifteen character and symbol limits would be bad enough on their own. For extra idiocy, though, they made their passwords case insensitive.
Who: Virgin Atlantic
What: Between 5 and 8(!) characters long, only notified after submit.
Why: Password requirement is incredibly low and insecure,
Rating: 1/5
Who: Citi
What: Be between 6 and 50 characters with 1 letter and 1 number, a haiku, a gang sign, a heiroglyph.
Why: Aside from the verbosity of requirements, they take pretty much any secure password you throw at them. Leave out the cheat sheet and just warn on form submit.
Score: 4/5
Who: Starwood Hotels SPG
What: No visible requirements.
Why: The lack of visible requirements bodes well until you start to typing only to find out that it just silently stops accepting input. When you consider the fact they use miniscule type size and if were blazingly typing a long password you’d never know they only save a portion of it. Even the security question answer is limited!
Who: Fidelity Investments
What: Who knows?
Why: Couldn’t find it! Bad, bad UX design.