Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 18 submissions in the queue.
posted by martyb on Friday August 19 2016, @07:32PM   Printer-friendly
from the keeping-things-to-yourself dept.

The latest NIST (United States National Institute for Standards and Technology) guidelines on password policies recommend a minimum of 8 characters. Perhaps more interesting is what they recommend against. They recommend against allowing password hints, requiring the password to contain certain characters (like numeric digits or upper-case characters), using knowledge-based authentication (e.g., what is your mother's maiden name?), using SMS (Short Message Service) for two-factor authentication, or expiring passwords after some amount of time. They also provide recommendations on how password data should be stored.

[Ed. Note: Contrary to common practice, I would advocate reading the entire linked article so we can have an informed discussion on the many recommendations in the proposal. What has been your experience with password policies? Do the recommendations rectify problems you have seen? Is it reasonable to expect average users to follow the recommendations? What have they left out?]


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Interesting) by hendrikboom on Friday August 19 2016, @09:31PM

    by hendrikboom (1125) Subscriber Badge on Friday August 19 2016, @09:31PM (#390301) Homepage Journal

    Is there any hope for people with mobility disorders, such as Parkinson's, who cannot type correctly? Or, for that matter, people whose laptops have bouncy keys?

    These people need to be able to *see* the passwords they are typing.

    -- hendrik

    Starting Score:    1  point
    Moderation   +1  
       Interesting=1, Total=1
    Extra 'Interesting' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3  
  • (Score: 0) by Anonymous Coward on Sunday August 21 2016, @12:09AM

    by Anonymous Coward on Sunday August 21 2016, @12:09AM (#390797)

    There are other input devices than keyboards. Also, I usually turn on "bounce keys" at its lowest level on any computer due to shitty keyboards.

  • (Score: 2) by urza9814 on Monday August 22 2016, @10:18PM

    by urza9814 (3954) on Monday August 22 2016, @10:18PM (#391899) Journal

    These people need to be able to *see* the passwords they are typing.

    Some places have been making passwords visible *by default* lately. Those morons over at Amazon.com are one such example, although I think that only occurs on certain devices so far.