NIST Revises Identity Guidelines, Including Password Requirements

CYMI last week, Finally after we have been hounding them for 15 years, NIST Revised their Identity Guidelines, Including Password Requirements (SP800-63-4) suggesting that credential service providers (CSPs) stop recommending passwords using several character types and stop mandating periodic password changes unless the authenticator has been compromised. Other notable recommendations include passwords between 15 and 64 characters long and CSPs should allow ASCII and Unicode characters to be included in passwords. Accessible here:

https://pages.nist.gov/800-63-4/sp800-63.html?is=6055c60558f128c7d4263ed6b32d80434f235971f8bf2e5a51be468de2a1bd9e

#nist #passwords #credentials #guidelines #hackproofyourself #boardroomsecurity #cybersecurity #infosec #danweis

Previous
Previous

It's Cyber Security Awareness Month!

Next
Next

Look out for these new style phishing campaigns!