this post was submitted on 26 Sep 2024
91 points (100.0% liked)

Cybersecurity

5687 readers
57 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 39 points 1 month ago (4 children)

The latest NIST guidelines now state that:

Verifiers and CSPs SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords and
Verifiers and CSPs SHALL NOT require users to change passwords periodically. However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.
[–] [email protected] 7 points 1 month ago (2 children)

Please don’t take those recommendations out of context.

They also recommend MFA, but people only ever bring up the “no rotation” bit.

[–] [email protected] 5 points 1 month ago

Are they at least recommending non-SMS MFA now?

[–] [email protected] 4 points 1 month ago

Emphasis was from the article, not mine.

They also recommend not using knowledge based prompts, allowing at least 64: characters,

load more comments (1 replies)