You must use at least one uppercase letter,Landlady’s Loose Legs a symbol, and a number. Or, wait, maybe not.
According to the experts at the National Institute of Standards and Technology (NIST), some of the password-strength requirements drilled into our skulls over the years are actually not that helpful.
What's worse, they may be counterproductive.
SEE ALSO: New tool teaches you how to set stronger passwordsAs such, the institute issued a new draft of security guidelines on May 11, 2017, aimed at security professionals and recommending several significant changes to the password requirements we've come to accept as a necessary part of life.
What's different? Well, for one, the experts say that forcing users to create passwords which include numbers and random characters is no longer necessary.
"[Online] services have introduced rules in an effort to increase the complexity of [passwords]," reads the draft appendix. "The most notable form of these is composition rules, which require the user to choose passwords constructed using a mix of character types, such as at least one digit, uppercase letter, and symbol. However, analyses of breached password databases reveals that the benefit of such rules is not nearly as significant as initially thought, although the impact on usability and memorability is severe."
Basically, passwords full of #'s and &'s are hard to remember, and they don't actually offer that much of a benefit. Instead, NIST recommends that people be allowed to choose any password of 8 characters or more — with a catch.
The catch being that whatever the user selects should be compared against a list of known common passwords. Lists of stolen passwords exist, and if the key to your email account is something like "monkey" then NIST says it should be rejected.
Who is doing the work of comparing your desired password against the aforementioned list? Don't worry, it's not you. Instead, that responsibility would theoretically fall to whatever service you're trying to create an account with.
What else does NIST throw out the digital window? Why that would be a little annoying thing called forced password resets. That's right, it turns out obligating users to change their passwords — regardless of any data breaches or lack thereof — is counterproductive. Of course, if a company discovers it's been hacked, you should still be required to reset your login information.
The experts at NIST also go after what is a huge pet peeve of mine: security questions. Preset security questions that a user is forced to fill out, like "what high school did you attend," are easily discovered by hackers via a simple Google search (as Sarah Palin once painfully discovered) and should be done away with entirely.
"Verifiers also SHALL NOT prompt subscribers to use specific types of information (e.g., 'What was the name of your first pet?') when choosing memorized secrets," the draft declaratively states. Nice.
So, to recap: No special characters required, no forced password resets, and no fixed (easily guessable) security questions. It's almost like all the password security advice we've been given is wrong.
Except that chestnut about using two-factor authentication. You should still definitely do that.
Topics Cybersecurity
Facebook bans hashtag searches for #StopTheSteal and #SharpieGate conspiracy theoriesFor a brief, beautiful moment, Bing's homepage featured a penisTrump lost. A divided America must move forward and reject Trumpism.Watching "The Mandalorian"? Try Baby Yoda Cuteness BingoThe new MacBook Air and MacBook Pro are powered by Apple's own M1 chipIn praise of taking yourself seriously on dating apps'Legend of Korra' is a sophisticated series for ambivalent timesIcy moon Europa may glow in the dark, experiments suggestNot even Fox News could find a Republican willing to defend TrumpOkay forget the White Walker kidnapping plan, I've got plenty of other ideas. By Jon SnowEvery Bentley will be totally electric by 2030Facebook bans hashtag searches for #StopTheSteal and #SharpieGate conspiracy theoriesAfter ban, new 'Stop the Steal' Groups spread conspiracy theories on FacebookJ.K. Rowling tweets heartbreaking video of Heather Heyer's motherUpdate your iPhone to iOS 14.2 right now if you want to keep it secureCéline Dion dancing at her son's hockey game is the motivation you probably need todayFacebook pulls 'Gay Communists for Socialism' group which trolled Trump supportersNotice of data security incidentUpdate your iPhone to iOS 14.2 right now if you want to keep it secureNot even Fox News could find a Republican willing to defend Trump Michelle Obama doesn't want to run for president, and yet we continue to ask her Private prison stocks soar after Donald Trump wins presidency How a little The Mountain from 'Game of Thrones' posts extremely hype Lyft pulled electric bikes off the streets in NY, SF, and D.C. The world's largest plane, the Stratolaunch, just took flight Brie Larson and Oprah bonding over 'Queer Eye' is absolutely perfect Facebook investors launch desperate bid to oust Mark Zuckerberg Australia's newspapers aren't holding back on hot Trump takes Chrissy Teigen got kicked out of John Legend's 'Game of Thrones' viewing party This Donald Trump waxwork will send shivers down your spine Tesla's self This moving fan story about George R.R. Martin will make you tear up Powerful Mannequin Challenge video highlights the Black Lives Matter movement Apple vs. Qualcomm: Everything you need to know The 'Here we go again' meme is perfect for every frustrating situation All 'Game of Thrones' Season 8 premiere reunions ranked by awkwardness All the pilot parallels in the 'Game of Thrones' Season 8 premiere Rise up: America’s students stage school walkouts following Trump victory Pete Buttigieg's kiss with Chasten was a radical moment
1.963s , 10139.0234375 kb
Copyright © 2025 Powered by 【Landlady’s Loose Legs】,Charm Information Network