NIST proposes barring some of the most nonsensical password rules

https://lemmy.world/post/20190319

NIST proposes barring some of the most nonsensical password rules - Lemmy.World

Here is the text of the NIST sp800-63b [https://pages.nist.gov/800-63-4/sp800-63b.html] Digital Identity Guidelines.

Reworded rules for clarity:

  • Min required length must be 8 chars (obligatory), but it should be 15 chars (recommended).
  • Max length should allow at least 64 chars.
  • You should accept all ASCII plus space.
  • You should accept Unicode; if doing so, you must count each code as one char.
  • Don’t demand composition rules (e.g. “u’re password requires a comma! lol lmao haha” tier idiocy)
  • Don’t bug users to change passwords periodically. Only do it if there’s evidence of compromise.
  • Don’t store password hints that others can guess.
  • Don’t prompt the user to use knowledge-based authentication.
  • Don’t truncate passwords for verification.
  • I was expecting idiotic rules screaming “bureaucratic muppets don’t know what they’re legislating on”, but instead what I’m seeing is surprisingly sane and sensible.

    NIST generally knows what they’re doing. Want to overwrite a hard drive securely? NIST 800-88 has you covered. Need a competition for a new block cipher? NIST ran that and AES came out of it. Same for a new hash with SHA3.
    Didn’t know about sha3.

    NIST generally knows what they’re doing

    For now, at least. Could change after Inauguration Day.