HomeinetNIST finally changes password policy

NIST finally changes password policy

The United States National Institute of Standards and Technology (NIST) is formulating new guidelines for the policies that passwords used by the US government and the public sector in general should follow.

Anyone interested in the new specifications of Special Publication 800-63-3: Digital Authentication Guidelines can be found on the NIST website.

But let's see what are the main differences between today's policy and the one recommended by NIST?NIST passwords

Some of NIST's new recommendations you can probably guess, and others may surprise you.

Let's begin:

The new policies favor the user. In other words, websites should stop asking users to do things that don't actually improve security.

Many of the so-called "best practices" turn out to be insufficient and not worth the headache they cause.

Size matters for passwords. The new NIST guidelines state that you should have at least 8 characters. This should not be the upper limit, so you can increase the password length on more sensitive accounts.

NIST says that a maximum length of at least 64 characters should be allowed, so there should be no more “Sorry, your password cannot be longer than 16 characters.”

All printable ASCII characters should be allowed, including spaces, all UNICODE characters, and even Emoji!

Checking new passwords for inclusion in known cracking dictionaries. This way, no one will be able to use passwords like: ChangeMe, thisisapassword, 12345678, and so on.

Things you shouldn't do.

There are no password composition rules. This means you won't have to remember any more rules that force the use of specific characters or combinations, such as the slang terms on some password reset pages that require:

“Your password must contain one lowercase letter, one uppercase letter, one number, four symbols but not &% # @ _, and 5 kilos of skewers.”

The new regulations will allow users to choose freely, and encourage them to use long phrases that they can remember instead of deceptively complex passwords like pA55w + rd.

No more password hints. No more questions to help you remember your password if you forget it. In 2013, with the Adobe password leak, we saw some crazy stuff. Someone with the username password had the password hint assword!

Knowledge-based authentication (KBA) questions are no longer a thing. They're when a site asks you to Choose from a list of questions like Where did you go to high school? What's your favorite football team? and you have to type in the answer. You'll use it in case you need to verify your identity.

No more password expirations: My favorite new rule! If a user is using a very difficult and long 50-character password, why change it every month?
Passwords should only be changed when they have been forgotten, if they have been phished, or if you think (or know) that your password database has been stolen and could potentially be subjected to an offline brute-force attack.

NIST also gives some very valuable advice.

All passwords must be hashed, salted, and stretched with a salt of 32 bits or more, HMAC hash using SHA-1, SHA-2, or SHA-3, and a PBKDF2 “stretching” algorithm with at least 10,000 iterations.

Additionally, another big change is that SMS should no longer be used for two-factor authentication, as there are many problems with the security of SMS delivery, malware that can redirect text messages and attacks against the mobile network (such as the so-called SS7 hack), but also simple number portability.

Should we also mention SIM swaps? It's very easy to get a new SIM from your mobile provider and cancel the one you're using because it was supposedly lost, damaged, or stolen.

In many countries, unfortunately, it is very easy for criminals to convince a mobile phone shop to transfer someone's phone number to a new SIM card.

NIST's move was expected as password policies should constantly evolve as hacker techniques evolve.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS