3 ms·
Great, NIST put out objectively bad password guidance for a couple of decades and then decides to change it to a more sane solution. Too bad a GIANT swath of p
by fallous 2y ago
Great, NIST put out objectively bad password guidance for a couple of decades and then decides to change it to a more sane solution. Too bad a GIANT swath of password-protected software was built on their prior incompetent guidance and will take decades for all of that software to change... if they change at all.
- AmericanChopper 2y agoThese password guidelines were the state of the art at the time they were popularised. It really only becomes obvious why they’re bad when you observe the knock on behaviours they encourage, and even then the only way to make them not bad is with the use of modern tooling like password managers. The world has been rather slow to move off this standard, but NIST has been a huge enabler of that, so I don’t think they deserve any hate for this. Not too long ago the NIST password guidance was THE authority that enabled regulated companies (like PCI companies) to migrate off password complexity requirements with a compensating control. There’s plenty of other toxic security ideas out there as well. I would argue any control that generates large amounts of user friction for a negligible security benefit is probably a net downgrade in security posture, as user friction just normalises a culture of circumvention. Hopefully authorities like NIST can lead the way in tackling many of those as well.
- PoachedEggs 2y ago> probably a net downgrade in security posture, as user friction just normalises a culture of circumvention There is even a CWE for this concept: “CWE-655: Insufficient Psychological Acceptability” > The product has a protection mechanism that is too difficult or inconvenient to use, encouraging non-malicious users to disable or bypass the mechanism, whether by accident or on purpose.
- AmericanChopper 2y agoHah, how interesting. I can’t believe I’ve never seen that one before.