6 ms·
These “baseline rules” come from NIST SP 800-63B, Appendix A, which is a surprisingly digestible document: https://pages.nist.gov/800-63-3/sp800-63b.html#appA h
by Artemis2 7y ago
These “baseline rules” come from NIST SP 800-63B, Appendix A, which is a surprisingly digestible document: https://pages.nist.gov/800-63-3/sp800-63b.html#appA https://pages.nist.gov/800-63-3/sp800-63b.html#appA
- Jaruzel 7y agoAnd the UK equivalent from the National Cyber Security Council is at: https://www.ncsc.gov.uk/collection/passwords/updating-your-approach https://www.ncsc.gov.uk/collection/passwords/updating-your-a... Fun anecdote... I spent 6 months last year designing and implementing a 'Self-Service' password reset portal system and password synchronisation system for 50k+ users in a large organisation, only for the organisation in question to switch to non-expiring passwords 1 week before deployment. Needless to say... usage of the system post deployment was almost non-existent. Ah well, at least I still got paid.