You must use at least one uppercase letter,dreary eroticism a symbol, and a number. Or, wait, maybe not.
According to the experts at the National Institute of Standards and Technology (NIST), some of the password-strength requirements drilled into our skulls over the years are actually not that helpful.
What's worse, they may be counterproductive.
SEE ALSO: New tool teaches you how to set stronger passwordsAs such, the institute issued a new draft of security guidelines on May 11, 2017, aimed at security professionals and recommending several significant changes to the password requirements we've come to accept as a necessary part of life.
What's different? Well, for one, the experts say that forcing users to create passwords which include numbers and random characters is no longer necessary.
"[Online] services have introduced rules in an effort to increase the complexity of [passwords]," reads the draft appendix. "The most notable form of these is composition rules, which require the user to choose passwords constructed using a mix of character types, such as at least one digit, uppercase letter, and symbol. However, analyses of breached password databases reveals that the benefit of such rules is not nearly as significant as initially thought, although the impact on usability and memorability is severe."
Basically, passwords full of #'s and &'s are hard to remember, and they don't actually offer that much of a benefit. Instead, NIST recommends that people be allowed to choose any password of 8 characters or more — with a catch.
The catch being that whatever the user selects should be compared against a list of known common passwords. Lists of stolen passwords exist, and if the key to your email account is something like "monkey" then NIST says it should be rejected.
Who is doing the work of comparing your desired password against the aforementioned list? Don't worry, it's not you. Instead, that responsibility would theoretically fall to whatever service you're trying to create an account with.
What else does NIST throw out the digital window? Why that would be a little annoying thing called forced password resets. That's right, it turns out obligating users to change their passwords — regardless of any data breaches or lack thereof — is counterproductive. Of course, if a company discovers it's been hacked, you should still be required to reset your login information.
The experts at NIST also go after what is a huge pet peeve of mine: security questions. Preset security questions that a user is forced to fill out, like "what high school did you attend," are easily discovered by hackers via a simple Google search (as Sarah Palin once painfully discovered) and should be done away with entirely.
"Verifiers also SHALL NOT prompt subscribers to use specific types of information (e.g., 'What was the name of your first pet?') when choosing memorized secrets," the draft declaratively states. Nice.
So, to recap: No special characters required, no forced password resets, and no fixed (easily guessable) security questions. It's almost like all the password security advice we've been given is wrong.
Except that chestnut about using two-factor authentication. You should still definitely do that.
Topics Cybersecurity
Hands on with Apple macOS Mojave: It’s getting dark in hereNew Google Maps features just started rolling out — do you have them?Facebook ends its Aquila drone project'The Notebook' anniversary: Film spotlighted an important issueHear me out: Adults should listen to lullabies, tooCryptocurrency ads are coming back to FacebookDude masterfully sneaks in WuWorld Cups fans of Senegal and Japan give us a heartGoogle Assistant on Home devices now speaks and understands SpanishThe 'Westworld' Season 2 finale explained by its creatorsThis theory will make you look at Harry Potter in a totally new lightVolkswagen's all'Simpsons' fans dream of a Mexico and Portugal World Cup finalThis blueberry filled with a spider's nest would ruin anyone's breakfastThe 10 best new shows of 2018 (so far)Microsoft says its facial recognition software is less biasedAcademy invites Daniel Kaluuya, Timothée Chalamet, and 926 other new membersVenmo releases physical debit cardStephen Colbert, Jimmy Fallon, Conan O'Brien unite for Trump responseScientists have finally come up with a solution for the world's most annoying household sound Facebook now lets you export posts directly to Google Docs and WordPress Cadillac's first electric SUV will arrive early for just under $60,000 5 fantastic free coloring apps Apple's iPhone 13 will come with faster 5G in more countries, report claims Politician calmly handles confrontation with far 7 hidden Spotify features you probably didn't know about Why the spectacular Muldrow Glacier is surging in Alaska Chevy pushes out Tesla for 'best EV' in U.S. News awards Everything wrong with the reaction to Louis C.K.'s "apology" More than a dozen Democratic Socialists won last night in a wave of rose emojis Bright brows are the offbeat beauty look that works for everyone Fox News barely mentioned Tuesday's elections—which just so happened to be Democratic wins Dogecoin is mooning, and we're listening for the popping sound How to listen to audiobooks: Free apps vs. paid subscriptions All the big trailers Oculus showed at its first Gaming Showcase A second 'Downton Abbey' movie is in the works Edward Snowden's NFT 'Stay Free' just sold for over $5 million Obama is at jury duty and jury duty doesn't seem so bad anymore 'Solar Opposites' Season 2 Review: 'Rick and Morty' level of greatness Amazon reportedly plans to make drivers double as furniture installers
2.6491s , 10195.671875 kb
Copyright © 2025 Powered by 【dreary eroticism】,Creation Information Network