NIST Recommends Some Common-Sense Password Rules
ID: 2b550b40-58bc-5236-8645-ac8e8b6a5696
STIX ID: report--2b550b40-58bc-5236-8645-ac8e8b6a5696
Feed Name: Schneier on Security
NIST’s draft SP 800-63-4 recommends modernizing password policies: require at least 8 characters (preferably 15), permit up to 64 characters, accept all printable ASCII and Unicode, avoid composition rules and periodic resets except after compromise, prohibit password hints and knowledge-based security questions, and verify the full password without truncation. The post also notes potential security concerns with allowing arbitrary Unicode in passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
