10 ms·
Perhaps surprisingly, US government guidelines exist, are pretty fantastic, and agree with the author: Memorized secrets SHALL be at least 8 characters in le
by colinclerk 5y ago
Perhaps surprisingly, US government guidelines exist, are pretty fantastic, and agree with the author:
Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. If the CSP or verifier disallows a chosen memorized secret based on its appearance on a blacklist of compromised values, the subscriber SHALL be required to choose a different memorized secret. No other complexity requirements for memorized secrets SHOULD be imposed.
It's called NIST 800 63-B and available here: https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
Shameless plug - I'm the cofounder of Clerk and we handle passwords in a sane way out-of-the-box: https://clerk.dev/features/passwords https://clerk.dev/features/passwords
- deleted 5y ago[deleted]
- 6LLvveMx2koXfwn 5y ago6 characters in length seems a bit shoddy.
- wccrawford 5y agoYeah, bump that to 8 and it's more reasonable. And if it's already required to be randomly chosen, why not 10?
- deleted 5y ago[deleted]
- xboxnolifes 5y agoIt's not 10 because it still needs to be memorized.
- bombcar 5y agoThat’s the key people are missing. There’s a trade-off (though people can easily memorize phone numbers for example) when the password gets to complicated and you have to write it down.
- jihadjihad 5y agoI know it's hard to imagine, but before we all held supercomputers in our pockets we all used to have dozens of ten-digit numbers memorized. I still remember my grade school friends' phone numbers.
- adventured 5y agoYou were an extreme outlier if you bothered to memorize dozens of ten digit phone numbers in the era before everyone had a cellphone. The average person doesn't even have ten good friends, much less a need to memorize dozens of phone numbers. They would buy address books / contact books to write down dozens of numbers, not memorize numbers they very rarely use.
- dylan604 5y agoOr even more niche in your outlier status if you could remember IPs of the commonly used servers without a DNS in place. Most of the time, local networked IPs all start with the same values for the first 3 octets (maybe 2 if VLAN but then usually only one digit diff). The same was true for most people's local phone number memorized registry. Those of us old enough, we only had to dial 5 digits using (70s) the last number of the prefix before eventually moving to 7 digits to include the full prefix (80s). The world suddenly changed when we had to dial the entire area code as well (90s).
- karaterobot 5y agoI think "dozens" is an overstatement, but 10-20 wasn't unusual. In college, I could have given you the number for a dozen delivery restaurants, easily. Not proud of it, just saying. That's not counting family, friends, services like taxi companies and movie theaters, and work.
- tempnow987 5y agoRate limit the requests. Do an account lockout with an email click to re-enable after 10 guesses, do 2FA on new devices and you get pretty good security. For many systems, users can memorize 6 digits easily. The reality is, whatever your password reset flow is is enough. If you can reset your password with a 6 digit number via text, then that is maximum needed for actual password as well in most cases.
- marcosdumay 5y agoNone of that will help you if your hash database leaks. But I'm ok with letting the decision with the user.
- tempnow987 5y agoInteresting. In most cases if hash database leaks, the ability to crack depends on two factors, not one (password and hash difficulty) assuming you are salting properly. You can specify pretty high difficulty with argon2id etc. Ie, shoot for a one second runtime with a very high memory requirement (you can go to GB range even). So I'm not sure all is always necessarily lost
- Darmody 5y ago6 characters and entirely numeric seems like a bad idea, or am I missing something?
- sigstoat 5y agoI interpreted it backwards, "if you want to use a numeric keypad for controlling access to something, the codes MUST be at least 6 digits long, and you MUST assign them"
- pkulak 5y agoIt's fine if there's no way an attacker can execute a brute-force attack. And that can even be prevented in hardware. The iPhone is a good example.
- seanw444 5y agoThat provides one million possibilities. I don't think you're missing anything. That's pretty terrible. The only thing prolonging your account at that point is the service's rate-limiting, assuming a naive "enter this password in the login field, try it, repeat."
- kube-system 5y agoOn the other hand, if you have too many password requirements and the user can’t remember it, they often lean on bad password hygiene, and the password ends up being reused (and inevitably leaked) or written down somewhere.
- b3morales 5y agoThe numeric-only stipulation was in the "Memorized secrets chosen randomly by the CSP or verifier" category. Not chosen by the user.
- joshvm 5y agoRate limiting can be practically strong for everyday use. Bank PINs are commonly 4 digits, though the chip+PIN system allows up to at least 6. Three attempts and the card is locked. Provided you stop users from picking obvious numbers like birthdays, it's pretty effective at preventing card fraud. Weak passwords can be fine, provided rate limiting is extremely aggressive. You can adjust this based on access e.g. your admin account might be locked under stricter heuristics like a single attempted login outside your geographic region (Live mail does this to me sometimes). In this case the user might even have the correct password, but if something else doesn't add up then you can block.