I don’t think X is the right platform to share thoughts and have meaningful discussions anymore. I’m not learning here. I only see hate and X’s owner is misusing it for his own hateful agenda.
This is a definitive good bye.
Please share this far and wide. As far and wide as you can. NIST Password Guidelines for 2024 are in the process of being updated.
This is a HUGE pet-peeve of mine (when vendors in particular are still operating like its 2017 and keep changing passwords every 60 days, STOP DOING THIS, it's outdated and has been shown to put you MORE at risk than less -- NIST explains why it does in this document, meticulously outlining user behavior**) so I'm sharing this in the hopes all of you will pass it along to your bosses.
The Special Publication series governing passwords is SP 800-63 "Digital Identity Guidelines".
The 2024 version is 800-63-4.
Here: https://t.co/oX8YEJHxXg
The companion docs are also on that link. They are 800-63A, 800-63B and 800-63C. These are different documents for different scenarios in play at your org.
The previous update was in2020.
The changes in the 2020 version from the 2017 version were numerous but one of them was that the password verification method should NO LONGER require passwords be changed at specific intervals (i.e. every 60 days) but in the following circumstances instead:
1. After a breach/compromise
2. User request
2024 repeats this and adds a bunch more guidlines but here is a screenshot of page 13 of the new 800-63-4 (note the # 4 after it) which outlines how your systems should now and moving forward, be handling passwords.
This goes for Active Directory, too. All your systems which have passwords should align with these guidelines provided there isn't another standard or framework you must adhere to which overrules this.
Most frameworks, however, have moved away from arbitrary password resets and complexity rules.
**We cybersec researchers and hackers use wordlists from breaches in a variety of different ways. Hackers use them in tooling to crack passwords whereas researchers use breach dumps to see the kinds of passwords users are creating and the psychology behind them.
Using complexity rules gets you the user psychology of:
Password1
Password2
and so on
Use phrasing instead and allow for spaces, which is important. Humans type phrases with spaces. They also mention phish-resistant methods and most vendors are on-board with MS going to be turning off all Legacy Auth next month, across all free accounts and tenancies.
I'm so excited for the new changes!
Ok I'm off my soapbox.
Share the love! Thank you!
Even @CNN can’t spell properly anymore. Is there anyone who still knows the difference between “its” and “it’s”, “whose” and “who’s” and “there” and “their”?
@George_Kurtz Literally millions of people can’t travel to their loved ones, can’t transfer much needed funds, can’t have the long-awaited surgery… this is the impact
@George_Kurtz Such a bad response from a CEO. Here’s the example of the wrong tone of voice when your company’s fault has such a huge impact on customers. Where’s the empathy? Where’s the apology?
Definitely an interesting read. Whether they can hold up the promise will have to be seen next year, but it’s certainly a different take on AI that I like.
https://t.co/YlZsuAP9h1
@RJ_Derksen regel 13.1d mbt bal die op de green beweegt: de bal van Ryu bewoog nadat ze hem had gemarkeerd en teruggeplaatst. Dan moet ie vanaf die gemarkeerde plek worden gespeeld, dus wat ze deed was correct #lpga#ChevronChampionship
Het is tijd voor een echt verschillende politieke aanpak van de grote uitdagingen: klimaat en armoede zijn alleen in goede handen bij links. Stem GroenLinks-PvdA! Het gaat om solidariteit in deze wereld, niet om individualisme!
@RJ_Derksen waarom mocht McIntyre het vaste obstakel ontwijken? Hij lag toch in de hindernis? Volgens regel 16.1a mag je in een hindernis nooit relief krijgen.
I believe Apple Vision Pro is a game changer for AR. Not because it’s perfect but because Apple put every possible sensor, camera, display and computing power in it to make it work. It’ll be mind-blowing what you can do with it. In a few years it’ll be slim, elegant and useful.
@sander@sndrv Aanmeldingsdatum is leidend als je een patent wilt weerleggen. In dit geval 15/09/2021. Indien je “prior art” hebt van voor die datum, kun je dit aan EPO laten zien: https://t.co/ZgxfzQBK4R