You must use at least one uppercase letter,TV Movie Archives a symbol, and a number. Or, wait, maybe not.
According to the experts at the National Institute of Standards and Technology (NIST), some of the password-strength requirements drilled into our skulls over the years are actually not that helpful.
What's worse, they may be counterproductive.
SEE ALSO: New tool teaches you how to set stronger passwordsAs such, the institute issued a new draft of security guidelines on May 11, 2017, aimed at security professionals and recommending several significant changes to the password requirements we've come to accept as a necessary part of life.
What's different? Well, for one, the experts say that forcing users to create passwords which include numbers and random characters is no longer necessary.
"[Online] services have introduced rules in an effort to increase the complexity of [passwords]," reads the draft appendix. "The most notable form of these is composition rules, which require the user to choose passwords constructed using a mix of character types, such as at least one digit, uppercase letter, and symbol. However, analyses of breached password databases reveals that the benefit of such rules is not nearly as significant as initially thought, although the impact on usability and memorability is severe."
Basically, passwords full of #'s and &'s are hard to remember, and they don't actually offer that much of a benefit. Instead, NIST recommends that people be allowed to choose any password of 8 characters or more — with a catch.
The catch being that whatever the user selects should be compared against a list of known common passwords. Lists of stolen passwords exist, and if the key to your email account is something like "monkey" then NIST says it should be rejected.
Who is doing the work of comparing your desired password against the aforementioned list? Don't worry, it's not you. Instead, that responsibility would theoretically fall to whatever service you're trying to create an account with.
What else does NIST throw out the digital window? Why that would be a little annoying thing called forced password resets. That's right, it turns out obligating users to change their passwords — regardless of any data breaches or lack thereof — is counterproductive. Of course, if a company discovers it's been hacked, you should still be required to reset your login information.
The experts at NIST also go after what is a huge pet peeve of mine: security questions. Preset security questions that a user is forced to fill out, like "what high school did you attend," are easily discovered by hackers via a simple Google search (as Sarah Palin once painfully discovered) and should be done away with entirely.
"Verifiers also SHALL NOT prompt subscribers to use specific types of information (e.g., 'What was the name of your first pet?') when choosing memorized secrets," the draft declaratively states. Nice.
So, to recap: No special characters required, no forced password resets, and no fixed (easily guessable) security questions. It's almost like all the password security advice we've been given is wrong.
Except that chestnut about using two-factor authentication. You should still definitely do that.
Topics Cybersecurity
Apple, Google ban GPS data collection for COVIDTom Cruise and NASA team up to shoot a movie in spaceDaniel Radcliffe and more read first Harry Potter book on SpotifyDude almost flips directly into oncoming traffic and Twitter is shook2 hidden details in 'The Office' you've probably never noticedMcDonald's ad about a boy, his dead father and FiletReview: Netflix's 'Trial by Media' delivers solid true crime anthologyThunderbolt bugs can expose a PC if you leave it alone with a hackerWant to help others in a pandemic? Try these campaigns through Giving Tuesday Now.Rumor has it that a new Apple TV is 'ready to ship'Yeast scientist has some bad news about your sourdough starterDEF CON is actually, for real, not a joke canceledDaniel Radcliffe and more read first Harry Potter book on SpotifyDEF CON is actually, for real, not a joke canceledWhat is the best Harry Potter book?: Pop Culture ThrowdownRunners are using #IRunWithMaud to commemorate Ahmaud Arbery's lifeApple announces June 22 date for virtual WWDC eventYellow blush is the latest beauty trend taking over Instagram14 films and TV shows 'The Simpsons' perfectly predictedCareless truck driver gets a healthy dose of instant karma Watch Jimmy Fallon's surprise commencement speech at Marjory Stoneman Douglas High School Everything coming to Netflix in February 2022 Instagram will now show suspected hate speech lower in your Feed Google Assistant's new white noise is causing kids to throw tantrums Wildly sexist 'New York Post' front page refers to Kim Kardashian's butt 3 times Adele apologizes for Las Vegas residency postponement to fans via FaceTime The 'Where are you from?' meme reminds us to look at a map every once in a while The latest easter egg from Spotify celebrates Pride month How Stu Macher Unpacking Showtime's 'Yellowjackets' finale Father of child in thrilling Paris rescue now faces neglect charges Man's attempt to take panorama of dog goes horribly, horribly wrong Opera's new 'crypto browser' makes collecting NFTs shockingly easy Even drone newbies can take cinematic shots with Skydio's new mode Gifts for your trans dad this father's day The latest killer asteroid hype is just absurd No, New York City Mayor Eric Adams can't actually take his salary in bitcoin Fake 'CryptoPunk' hexagonal Twitter profile picture shows fatal flaw in its NFT plans Apple TV+'s 'Servant' Season 3 review: Finding beauty at a standstill pace This person's attempt to lie about their love of cars went very wrong, very fast
2.7486s , 10131.5234375 kb
Copyright © 2025 Powered by 【TV Movie Archives】,Unobstructed Information Network