You must use at least one uppercase letter,gay sex videos ass eating a symbol, and a number. Or, wait, maybe not.
According to the experts at the National Institute of Standards and Technology (NIST), some of the password-strength requirements drilled into our skulls over the years are actually not that helpful.
What's worse, they may be counterproductive.
SEE ALSO: New tool teaches you how to set stronger passwordsAs such, the institute issued a new draft of security guidelines on May 11, 2017, aimed at security professionals and recommending several significant changes to the password requirements we've come to accept as a necessary part of life.
What's different? Well, for one, the experts say that forcing users to create passwords which include numbers and random characters is no longer necessary.
"[Online] services have introduced rules in an effort to increase the complexity of [passwords]," reads the draft appendix. "The most notable form of these is composition rules, which require the user to choose passwords constructed using a mix of character types, such as at least one digit, uppercase letter, and symbol. However, analyses of breached password databases reveals that the benefit of such rules is not nearly as significant as initially thought, although the impact on usability and memorability is severe."
Basically, passwords full of #'s and &'s are hard to remember, and they don't actually offer that much of a benefit. Instead, NIST recommends that people be allowed to choose any password of 8 characters or more — with a catch.
The catch being that whatever the user selects should be compared against a list of known common passwords. Lists of stolen passwords exist, and if the key to your email account is something like "monkey" then NIST says it should be rejected.
Who is doing the work of comparing your desired password against the aforementioned list? Don't worry, it's not you. Instead, that responsibility would theoretically fall to whatever service you're trying to create an account with.
What else does NIST throw out the digital window? Why that would be a little annoying thing called forced password resets. That's right, it turns out obligating users to change their passwords — regardless of any data breaches or lack thereof — is counterproductive. Of course, if a company discovers it's been hacked, you should still be required to reset your login information.
The experts at NIST also go after what is a huge pet peeve of mine: security questions. Preset security questions that a user is forced to fill out, like "what high school did you attend," are easily discovered by hackers via a simple Google search (as Sarah Palin once painfully discovered) and should be done away with entirely.
"Verifiers also SHALL NOT prompt subscribers to use specific types of information (e.g., 'What was the name of your first pet?') when choosing memorized secrets," the draft declaratively states. Nice.
So, to recap: No special characters required, no forced password resets, and no fixed (easily guessable) security questions. It's almost like all the password security advice we've been given is wrong.
Except that chestnut about using two-factor authentication. You should still definitely do that.
Topics Cybersecurity
The 10 most bodacious '80s movies — and where to watch themPresidential debate livestream: How to watch BidenReneé Rapp and Rachel Sennott team up for Instagram's 'Close Friends Only' podcastXiaomi’s EV business ramps up hiring in preparation for overseas sales · TechNodeNASA spacecraft found a surprise within a surpriseCanada vs. Chile 2024 livestream: Watch Copa America for freeScientists find proof of unprecedented sun explosion hitting EarthBest iPad deal: Take $220 off an iPad Air (5th gen) at Best BuyPresidential debate livestream: How to watch BidenSK Hynix to produce HBM4 with TSMC's 3nm process, prototype in March 2025 · TechNodeReneé Rapp and Rachel Sennott team up for Instagram's 'Close Friends Only' podcastMassive authentication vulnerability risks compromising much of the internetNASA rover makes adventurous trip, then snaps stunning Mars pictureBaidu and Geely give no sign of investing further in EV joint venture · TechNodeBMW to achieve 100% green charging with China’s State Grid by 2027 · TechNodeNASA solar spacecraft keeps on going faster and faster and fasterBYD invests in DJI’s automotive subsidiary · TechNodeSex and reproduction studies in space offer confusing resultsArgentina vs. Peru 2024 livestream: Watch Copa America for freeBlack Myth: Wukong wins Best Action Game at TGA 2024, misses out on Game of the Year · TechNode Behold, the architectural legacy of millennials: Emoji on buildings 'Deadpool 2' just got upgraded to a summer date in the year of X American Airlines in hot water after flight attendant almost gets in fight with passenger This British teen standing up for gender equality is our feminist hero Tinder wants you to swipe right on this rhino to help save his species I tried an Instagram caption generator and the results were hilarious A group of 4 drones grounded 60 flights in a day, leaving 10,000 passengers stranded Serena Williams pens a sweet note to her future child Prince William gets squirted by marathon runner, has the time of his life Confessions of a dating app voyeur Starbucks baristas are now creating 'unicorn lemonade' and there's no end to this Jimmy Wales' new project is like Wikipedia, but to 'fix' the news Police finally stop 12 Cats have nine lives, but just in case, maybe don't hang out with a snake Marathon runner proposes to girlfriend minutes from finish line and it's too sweet You can probably (maybe?) trust this 'Avatar' sequel news, finally 'Guardians of the Galaxy Vol. 2' is Marvel at its most emotional India's relentless push for digital now reaches the hinterlands Man hatches fake terror plot to avoid holidaying with girlfriend Uber CEO Travis Kalanick claimed he was the 2nd best Wii Tennis player in the world
1.417s , 10521.328125 kb
Copyright © 2025 Powered by 【gay sex videos ass eating】,Unobstructed Information Network