4 ms·
Someday maybe the web will catch up with: “Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen rand
by osteele 9y ago
Someday maybe the web will catch up with: “Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. […] No other complexity requirements for memorized secrets SHOULD be imposed.” — 5.1.1.1 Memorized Secret Authenticators, NIST Special Publication 800-63B: Digital Identity Guidelines
Authentication and Lifecycle Management https://pages.nist.gov/sp800-63b.html https://pages.nist.gov/sp800-63b.html
- orf 9y ago> Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. Is that really secure? I mean, 6 numbers is not exactly a very strong secret.
- Terribledactyl 9y agoIt's fine if you can invalidate the secret after some finite number of tries and block a particular actor from attacking many accounts. And there's no leaking cross sites if someone obtains and breaks the salted hash db.
- jlgaddis 9y agoIt is for something like a CAC PIN.
- jlgaddis 9y agoWorking link: https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html