Nemeski to Cybersecurity@sh.itjust.worksEnglish • 3 months agoNIST proposes barring some of the most nonsensical password rulesarstechnica.comexternal-linkmessage-square8fedilinkarrow-up191arrow-down10cross-posted to: cybersecurity@sh.itjust.workstechnology@lemmy.world
arrow-up191arrow-down1external-linkNIST proposes barring some of the most nonsensical password rulesarstechnica.comNemeski to Cybersecurity@sh.itjust.worksEnglish • 3 months agomessage-square8fedilinkcross-posted to: cybersecurity@sh.itjust.workstechnology@lemmy.world
minus-square@UID_Zero@infosec.publinkfedilinkEnglish7•3 months agoPlease don’t take those recommendations out of context. They also recommend MFA, but people only ever bring up the “no rotation” bit.
minus-square@Zorsith@lemmy.blahaj.zonelinkfedilinkEnglish5•3 months agoAre they at least recommending non-SMS MFA now?
minus-square@linearchaos@lemmy.worldlinkfedilinkEnglish4•3 months agoEmphasis was from the article, not mine. They also recommend not using knowledge based prompts, allowing at least 64: characters,
Please don’t take those recommendations out of context.
They also recommend MFA, but people only ever bring up the “no rotation” bit.
Are they at least recommending non-SMS MFA now?
Emphasis was from the article, not mine.
They also recommend not using knowledge based prompts, allowing at least 64: characters,