Nemeski@lemm.ee to Cybersecurity@sh.itjust.worksEnglish · 1 month agoNIST proposes barring some of the most nonsensical password rulesarstechnica.comexternal-linkmessage-square8fedilinkarrow-up189arrow-down10cross-posted to: cybersecurity@sh.itjust.workstechnology@lemmy.world
arrow-up189arrow-down1external-linkNIST proposes barring some of the most nonsensical password rulesarstechnica.comNemeski@lemm.ee to Cybersecurity@sh.itjust.worksEnglish · 1 month agomessage-square8fedilinkcross-posted to: cybersecurity@sh.itjust.workstechnology@lemmy.world
minus-squareUID_Zero@infosec.publinkfedilinkEnglisharrow-up8arrow-down1·1 month agoPlease don’t take those recommendations out of context. They also recommend MFA, but people only ever bring up the “no rotation” bit.
minus-squareZorsith@lemmy.blahaj.zonelinkfedilinkEnglisharrow-up5·1 month agoAre they at least recommending non-SMS MFA now?
minus-squarelinearchaos@lemmy.worldlinkfedilinkEnglisharrow-up4·1 month agoEmphasis was from the article, not mine. They also recommend not using knowledge based prompts, allowing at least 64: characters,
Please don’t take those recommendations out of context.
They also recommend MFA, but people only ever bring up the “no rotation” bit.
Are they at least recommending non-SMS MFA now?
Emphasis was from the article, not mine.
They also recommend not using knowledge based prompts, allowing at least 64: characters,