- doesn't allow to use password managers because their login forms are full of terrible JavaScript making sure nothing gets pasted
- using "security questions" for account recovery which could be easily "cracked" using social engineering
- SMS based 2FA
- max password length of 32 chars
- fixed keysize of 2048/RSA for APNS certificates, 4096 will be rejected
- doesn't allow to use password managers because their login forms are full of terrible JavaScript making sure nothing gets pasted
- using "security questions" for account recovery which could be easily "cracked" using social engineering
- SMS based 2FA
- max password length of 32 chars
- fixed keysize of 2048/RSA for APNS certificates, 4096 will be rejected