Your passwords don’t need so many fiddly characters, NIST says
ID: beb03f6e-d77d-55bd-86d1-63fe7a12febb
STIX ID: report--beb03f6e-d77d-55bd-86d1-63fe7a12febb
Feed Name: Malwarebytes Blog
This report outlines NIST’s updated password guidance: prioritize longer passwords over complexity rules, eliminate scheduled password resets in favor of resets only after compromise, replace security questions and hints with recovery codes/links, and implement password blocklists (including breached and common terms). It recommends minimum lengths of 15 characters for single-factor authentication and 8 for MFA, allowing up to 64 characters, and encourages organizations—especially small businesses—to adopt these practices as modern, effective defenses against credential abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
