The don'ts list is pretty much a christmas present from NIST. I hate all of those things. Worst is the stupid security questions.
Apple still uses those and it annoys me. Yes, others still use them too, but I give Apple extra crap because I think they should know better by now but either they don't or don't care.
NIST’s new password rules – what you need to know
111–120 of 237 posts
Re: NIST’s new password rules – what you need to know
#112The importance of this NIST standard cannot be understated. It has a requirement that passwords be hashed with a random salt ! Microsoft Active Directory does not use salts ! I am trying to imagine the consequences to all the businesses and agencies that must adhere to these standards suddenly coming to the realization that they must replace their Active Directory installations and what that will mean for administeri…
The problem is they are basically saying that almost every "best pratice" recommended over the past 5-10 years is absolutely the wrong thing to be doing. Don't be surprised when people throw up their hands in frustration.
Re: NIST’s new password rules – what you need to know
#113The importance of this NIST standard cannot be understated. It has a requirement that passwords be hashed with a random salt ! Microsoft Active Directory does not use salts ! I am trying to imagine the consequences to all the businesses and agencies that must adhere to these standards suddenly coming to the realization that they must replace their Active Directory installations and what that will mean for administeri…
The problem is they are basically saying that almost every "best pratice" recommended over the past 5-10 years is absolutely the wrong thing to be doing. Don't be surprised when people throw up their hands in frustration.
I do one controversial think and that's trim password imput (mainly because of trailing whitespace selection in some apps/oses). Other than that, if you can input it, you can use it... though now doing some unicode normalization for unity combos is probably a good idea prior to hashing.
Re: NIST’s new password rules – what you need to know
#114It's great that there's now a "right answer", and it seems to be based on some solid research about what actually helps and what doesn't.
In a similar vein I wish there were somehow a standard for http login and change password requests. Right now password managers are pretty hit or miss about whether they can actually fill a form and log you in, sometimes it just can't find the right field, sometimes there's a javascript field check of some sort so you have to click into the field after the password manager fills it before you can submit, etc. Having some kind of a standard would let you more reliably be able to automate logging in, rotating all passwords (at least on accounts without MFA), etc.
Re: NIST’s new password rules – what you need to know
#115Earlier quoted context omitted.
There are quite a few scenarios where a sustained, hidden compromise is an (or several) order of magnitude worse than a one time obvious compromise. The first to come to mind is a corporate espionage scenario. Do you want to know what your competitor is up to today, or do you want access to their briefings/CAD/code for the next 12 months? Long duration compromises also allow you to slip data out slowly, so a NAS does…
The rotation guidance is partly to address employees who've left the company, vs generalized password cracking attempts.
Re: NIST’s new password rules – what you need to know
#116Earlier quoted context omitted.
That is the entirety of PCI PCI is nothing more than Security Theater so Mastercard and visa can claim it is all the merchants fault for data breaches and shield them from any liability
Credit card numbers themselves are security theater.
Re: NIST’s new password rules – what you need to know
#117Earlier quoted context omitted.
I had the opposite recently. Trying to log into my alma mater's website to get a copy of transcripts, but my account had long ago locked out. They asked me questions over the phone to reset it, but I couldn't answer any of them. "What is your phone number on file?" Shoot, I don't know, it was an old number that I changed maybe 6 years ago... "What is your address on file?" I've moved maybe five times since then? I tr…
I've found that the only known repository of all my previous addresses is Amazon. I really need to capture them to 1Password.
Re: NIST’s new password rules – what you need to know
#118Earlier quoted context omitted.
The rotation guidance is partly to address employees who've left the company, vs generalized password cracking attempts.
Then you've already failed my not having a plan to disable accounts
Also it's not just for the account of the terminated person, but for any passwords the terminated person has 'learned' whilst employed.
Re: NIST’s new password rules – what you need to know
#119Earlier quoted context omitted.
I had the opposite recently. Trying to log into my alma mater's website to get a copy of transcripts, but my account had long ago locked out. They asked me questions over the phone to reset it, but I couldn't answer any of them. "What is your phone number on file?" Shoot, I don't know, it was an old number that I changed maybe 6 years ago... "What is your address on file?" I've moved maybe five times since then? I tr…
I've found that the only known repository of all my previous addresses is Amazon. I really need to capture them to 1Password.
Re: NIST’s new password rules – what you need to know
#120Earlier quoted context omitted.
I've found that the only known repository of all my previous addresses is Amazon. I really need to capture them to 1Password.
Pull a free credit report--you get one per year by law. It should have all your past addresses on it, or at least within the last X years.