3 ms·
>that NIST has killed in competent circles Just because this is my favorite soapbox - anyone that has to deal with passwords should go read NIST SP800-63B: ht
by commandar 2y ago
>that NIST has killed in competent circles
Just because this is my favorite soapbox - anyone that has to deal with passwords should go read NIST SP800-63B:
https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
I was kind of shocked by just how gosh-darned reasonable it is when it came out a couple of years ago. It's my absolute favorite thing to cite during audits.
"Are you requiring password resets every 90 days?"
"No. We follow the federal government's NIST SP800-63B guidelines which explicitly states that passwords should not be arbitrarily reset."
I've been pleasantly surprised that I haven't really had an auditor push back so far. I'm sure I eventually will, but it's been incredibly effective ammunition so far.
- hathawsh 2y agoI've done the same thing, with the same results. These guidelines are impressive. 1Password created an excellent summary: https://blog.1password.com/nist-password-guidelines-update/ https://blog.1password.com/nist-password-guidelines-update/
- Jedd 2y agoAlas, in Australia one of the more popular frameworks in gov agencies is Essential Eight, and they are a few years away from publishing an update with this radical idea.
- NoPicklez 2y agoMy understanding is that Essential Eight doesn't require password rotation
- Jedd 2y agoIf so then I'll be doubly frustrated - I've been assured by our domain experts that this is a requirement of the model. Did it used to be and was since retracted? I suppose it may be a local or state-based 'implementation augmentation'. I've trawled just now through the signals directorate site and can find plenty of references to passwords, but nothing specifically covering this.
- NoPicklez 2y agoIt may have been as password rotation was a requirement thrown around, but to my knowledge it's not come up in assessments for a long time.