logo

Your passwords don’t need so many fiddly characters, NIST says

ID: beb03f6e-d77d-55bd-86d1-63fe7a12febb

STIX ID: report--beb03f6e-d77d-55bd-86d1-63fe7a12febb

Feed Name: Malwarebytes Blog

Date Published: 2025-10-10

Date Updated: 2026-04-28

...
...

This report outlines NIST’s updated password guidance: prioritize longer passwords over complexity rules, eliminate scheduled password resets in favor of resets only after compromise, replace security questions and hints with recovery codes/links, and implement password blocklists (including breached and common terms). It recommends minimum lengths of 15 characters for single-factor authentication and 8 for MFA, allowing up to 64 characters, and encourages organizations—especially small businesses—to adopt these practices as modern, effective defenses against credential abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.