• linearchaosEnglish
    arrow-up
    39
    arrow-down
    0
    ·
    20 days ago
    link
    fedilink

    The latest NIST guidelines now state that:

    Verifiers and CSPs SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords and
    Verifiers and CSPs SHALL NOT require users to change passwords periodically. However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.
    
    • halcyoncmdrEnglish
      arrow-up
      12
      arrow-down
      0
      ·
      20 days ago
      link
      fedilink

      Makes sense. Most compromises aren’t brute force attacks. Allow all the characters and any brute force that is attempted will have to assume they’re part of it.

      Removing required periodical changes means people are less likely to use the same password and just increment a number added to the end. A compromised password with a setup like that is still compromised, they can make an educated guess as to what the new number is based on when was compromised compared to now.

    • UID_ZeroEnglish
      arrow-up
      8
      arrow-down
      1
      ·
      20 days ago
      link
      fedilink

      Please don’t take those recommendations out of context.

      They also recommend MFA, but people only ever bring up the “no rotation” bit.

      • ZorsithEnglish
        arrow-up
        5
        arrow-down
        0
        ·
        20 days ago
        link
        fedilink

        Are they at least recommending non-SMS MFA now?

      • linearchaosEnglish
        arrow-up
        4
        arrow-down
        0
        ·
        20 days ago
        link
        fedilink

        Emphasis was from the article, not mine.

        They also recommend not using knowledge based prompts, allowing at least 64: characters,

  • AstridWipenaughEnglish
    arrow-up
    18
    arrow-down
    0
    ·
    20 days ago
    link
    fedilink

    This is the most excited I’ve been about a NIST standard in a good while

  • P03 LockeEnglish
    arrow-up
    3
    arrow-down
    0
    ·
    20 days ago
    edit-2
    20 days ago
    link
    fedilink

    NIST SP 800-63b already did that several years ago. People just need to follow it.