Site icon TheCyberThrone

NIST revises password requirements guidelines

Advertisements

The National Institute of Standards and Technology (NIST) came with a revision of its standard that no longer recommending using a mixture of character types in passwords or regularly changing passwords

NIST’s (SP 800-63-4)  draft password guidelines outlines technical requirements and best practices for password management and authentication.

When NIST first introduced its password recommendations (NIST 800-63B) in 2017, it recommended complexity: passwords comprising a mix of uppercase and lowercase letters, numbers. In recent years, NIST has shifted its focus to password length since longer passwords are harder to crack with brute-force attacks and can be easier for users to remember without being predictable.

Advertisements

Public comment on this draft (via email dig-comments@nist.gov) is open until 11:59 pm Eastern Time on Oct. 7.

Exit mobile version