Stories
Slash Boxes
Comments

SoylentNews is people

Submission Preview

Link to Story

Latest NIST Guidelines on Password Policies

Accepted submission by Bill Dimm at 2016-08-19 14:43:12
Security

The latest NIST guidelines on password policies [sophos.com] recommend a minimum of 8 characters. Perhaps more interesting is what they recommend against. They recommend against allowing password hints, requiring the password to contain certain characters (like numeric digits or upper-case characters), using knowledge-based authentication (e.g., what is your mother's maiden name?), or expiring passwords after some amount of time. They also provide recommendations on how password data should be stored.


Original Submission