NIST standards proposal looks to retire outdated authentication requirements like mandatory password resets
Technology tamfitronics Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust.That makes sense: What's more aggravating than having to change your password periodically? I worked for one company that required it every three months, plus they had all these other rules about what the password could and could not contain. Standard regulators now declare that most credential rules are obsolete and unnecessary. The National Institute of Standards and Technology (NIST) has proposed new credential standards it wishes to adopt. The second draft of Special Publication 800-63-4 is posted to the NIST website, awaiting public feedback on the suggested password and authentication guidelines.The outline of standards is no-nonsense but flies in the face of the annoying password regimen many companies and agencies employ. Some examples include mandating password resets, limiting character...
