▲ 91 ▼ NIST proposes barring some of the most nonsensical password rules (arstechnica.com) submitted 2 years ago by neme@lemm.ee to c/cybersecurity@sh.itjust.works 8 comments fedilink hide all child comments
[–] UID_Zero@infosec.pub 7 points 2 years ago (2 children) Please don’t take those recommendations out of context. They also recommend MFA, but people only ever bring up the “no rotation” bit. permalink fedilink source parent hideshow 4 child comments replies: [–] Zorsith@lemmy.blahaj.zone 5 points 2 years ago Are they at least recommending non-SMS MFA now? permalink fedilink source parent [–] linearchaos@lemmy.world 4 points 2 years ago Emphasis was from the article, not mine. They also recommend not using knowledge based prompts, allowing at least 64: characters, permalink fedilink source parent
[–] Zorsith@lemmy.blahaj.zone 5 points 2 years ago Are they at least recommending non-SMS MFA now? permalink fedilink source parent
[–] linearchaos@lemmy.world 4 points 2 years ago Emphasis was from the article, not mine. They also recommend not using knowledge based prompts, allowing at least 64: characters, permalink fedilink source parent