4 ms·
Disclosure: I am the cofounder https://www.clerk.dev https://www.clerk.dev Here's the direct link to NIST 800-63B - it's really a fantastic document with sensi
by colinclerk 5y ago
Disclosure: I am the cofounder https://www.clerk.dev https://www.clerk.dev
Here's the direct link to NIST 800-63B - it's really a fantastic document with sensible recommendations on every authentication method: https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
The tedious part of NIST's password requirements is "Do check for compromised passwords"
HaveIBeenPwned exists, but most open source tools don't leverage it and this requirement goes overlooked.
At Clerk, we follow NIST guidelines by default, including integration with HIBP. In a world with password reuse and "credential stuffing" attacks, this feature is critical to securing your user accounts (unless you go full passwordless, but that has its own tradeoffs).
- amanzi 5y agoThe important part is that the NIST password advice is meant to be read as a whole. Often I see people quote snippets out of the advice, but unless you read and understand the whole document, you run the risk of reducing your security posture.
- colinclerk 5y agoWhat's crazy to me is that NIST compliance isn't part of SOC-2 certifications or similar. A portion of our customers will ask us about NIST, but it's slimmer than I would have expected.
- Jeff_Brown 5y agoBut even if you didn't read all of it, and just required longer passwords instead of special characters, you'd be improving things.
- amanzi 5y agoThat's true, but I've also seen people say that NIST no longer recommend expiring passwords periodically, so we should just let passwords never expire (source: "Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)"). While that's technically true, the advice is meant to be taken in the context of the rest of the advice (e.g. longer passwords, checking against compromised passwords, etc...). If all you did was to change all your passwords to never expire, you'd be reducing security.
- MereInterest 5y ago> If all you did was to change all your passwords to never expire, you'd be reducing security. Not necessarily. Except in cases of gross negligence, such as storing passwords in plain text, the human is always the weak point in a security system. If you make people less likely to leave their passwords on sticky notes, perhaps by removing password rotation, then you have improved the weakest link of the system, and improved the security of the system as a whole.
- scoot 5y agoOff-topic, but this is the second time in two days that I've seem someone on HN correctly use "disclosure" when disclosing something, rather than "disclaimer". A sea change?! It's clueless, I know, but you'd be amazed at the percentage of people that think disclosing something is a disclaimer (sigh!)