Live data from Hacker News

NIST’s new password rules – what you need to know

nakedsecurity.sophos.com

111–120 of 237 posts

Re: NIST’s new password rules – what you need to know

#111
post #95
post #41

The don'ts list is pretty much a christmas present from NIST. I hate all of those things. Worst is the stupid security questions.

Apple still uses those and it annoys me. Yes, others still use them too, but I give Apple extra crap because I think they should know better by now but either they don't or don't care.

You can't change your existing password in apple if you forget your secret question/answer. I gave gibberish to these secret pet/school. Now I am unable to change my password ;-)

Re: NIST’s new password rules – what you need to know

#112

The importance of this NIST standard cannot be understated. It has a requirement that passwords be hashed with a random salt ! Microsoft Active Directory does not use salts ! I am trying to imagine the consequences to all the businesses and agencies that must adhere to these standards suddenly coming to the realization that they must replace their Active Directory installations and what that will mean for administeri…

The problem is they are basically saying that almost every "best pratice" recommended over the past 5-10 years is absolutely the wrong thing to be doing. Don't be surprised when people throw up their hands in frustration.

"best practice" according to whom and "recommended" by whom? Maybe by security theater or other sources of BS, but not security experts (who are worth their, ahem, salt).

Re: NIST’s new password rules – what you need to know

#113

The importance of this NIST standard cannot be understated. It has a requirement that passwords be hashed with a random salt ! Microsoft Active Directory does not use salts ! I am trying to imagine the consequences to all the businesses and agencies that must adhere to these standards suddenly coming to the realization that they must replace their Active Directory installations and what that will mean for administeri…

The problem is they are basically saying that almost every "best pratice" recommended over the past 5-10 years is absolutely the wrong thing to be doing. Don't be surprised when people throw up their hands in frustration.

It's been longer than 10 years, and known for quite some time by most.. The xkcd article is over 5yo itself, and a lot of people pushed for more open passwords for ages...

I do one controversial think and that's trim password imput (mainly because of trailing whitespace selection in some apps/oses). Other than that, if you can input it, you can use it... though now doing some unicode normalization for unity combos is probably a good idea prior to hashing.

https://xkcd.com/936/

Re: NIST’s new password rules – what you need to know

#114
I've written into several companies in the past saying "your password policy are bad for __ reason", and they always of course write back saying basically "our security team doesn't care, shut up". There've been quite a few times I've cancelled accounts right after signing up because of just how absurd they were (for instance I believe Trade King forces you to click type your password with the mouse on an on-screen keyboard just in case you have a keylogger malware).

It's great that there's now a "right answer", and it seems to be based on some solid research about what actually helps and what doesn't.

In a similar vein I wish there were somehow a standard for http login and change password requests. Right now password managers are pretty hit or miss about whether they can actually fill a form and log you in, sometimes it just can't find the right field, sometimes there's a javascript field check of some sort so you have to click into the field after the password manager fills it before you can submit, etc. Having some kind of a standard would let you more reliably be able to automate logging in, rotating all passwords (at least on accounts without MFA), etc.

Re: NIST’s new password rules – what you need to know

#115
post #106

Earlier quoted context omitted.

There are quite a few scenarios where a sustained, hidden compromise is an (or several) order of magnitude worse than a one time obvious compromise. The first to come to mind is a corporate espionage scenario. Do you want to know what your competitor is up to today, or do you want access to their briefings/CAD/code for the next 12 months? Long duration compromises also allow you to slip data out slowly, so a NAS does…

The rotation guidance is partly to address employees who've left the company, vs generalized password cracking attempts.

Then you've already failed my not having a plan to disable accounts

Re: NIST’s new password rules – what you need to know

#116
post #110
post #39

Earlier quoted context omitted.

That is the entirety of PCI PCI is nothing more than Security Theater so Mastercard and visa can claim it is all the merchants fault for data breaches and shield them from any liability

Credit card numbers themselves are security theater.

Not half as bad as Social Security Numbers.

Re: NIST’s new password rules – what you need to know

#117

Earlier quoted context omitted.

I had the opposite recently. Trying to log into my alma mater's website to get a copy of transcripts, but my account had long ago locked out. They asked me questions over the phone to reset it, but I couldn't answer any of them. "What is your phone number on file?" Shoot, I don't know, it was an old number that I changed maybe 6 years ago... "What is your address on file?" I've moved maybe five times since then? I tr…

I've found that the only known repository of all my previous addresses is Amazon. I really need to capture them to 1Password.

Pull a free credit report--you get one per year by law. It should have all your past addresses on it, or at least within the last X years.

Re: NIST’s new password rules – what you need to know

#118
post #106

Earlier quoted context omitted.

The rotation guidance is partly to address employees who've left the company, vs generalized password cracking attempts.

Then you've already failed my not having a plan to disable accounts

I haven't failed anything. I am not an IT pro.

Also it's not just for the account of the terminated person, but for any passwords the terminated person has 'learned' whilst employed.

Re: NIST’s new password rules – what you need to know

#119

Earlier quoted context omitted.

I had the opposite recently. Trying to log into my alma mater's website to get a copy of transcripts, but my account had long ago locked out. They asked me questions over the phone to reset it, but I couldn't answer any of them. "What is your phone number on file?" Shoot, I don't know, it was an old number that I changed maybe 6 years ago... "What is your address on file?" I've moved maybe five times since then? I tr…

I've found that the only known repository of all my previous addresses is Amazon. I really need to capture them to 1Password.

As bad as it probably is, I've kept it in google sheets going back a few years now...

Re: NIST’s new password rules – what you need to know

#120

Earlier quoted context omitted.

I've found that the only known repository of all my previous addresses is Amazon. I really need to capture them to 1Password.

Pull a free credit report--you get one per year by law. It should have all your past addresses on it, or at least within the last X years.

[deleted]
Post reply on HN