ICYMI: As covered by AP, more sites are joining the passkey movement for safer, easier logins. @andrewshikiar, says, "It's just a matter of time for more sites to adopt this technology." Ready to sign in faster with passkeys? Read on to find out more.
https://t.co/0lWv83bXrs
🚀 📹 New Video! Tired Of Passwords? So Are We! Free Yourself [From Passwords] With Passkeys! Watch this video and go PASSWORDLESS w/ PASSKEYS. Plus! Learn more about the benefits of using passkeys and how to get started by visiting the passkeys landing pg https://t.co/dhY0H3IvLd
The Chief of Staff of the Irish 🇮🇪 Defence Forces calls Israel’s 🇮🇱 strike against UN peacekeepers in Lebanon 🇱🇧 an ‘egregious violation’ that ‘cannot be tolerated’
Starmer 🇬🇧 is selling weapons to a pariah nation that is at war with the UN
He is guilty
If I’ve already proven who I am to an agency, I should be able to ask that agency to vouch for me when I need to prove who I am online.
This new NIST guidance will help agencies do that in a way that is secure and protects privacy.
One small platoon of Irish peacekeepers has refused Israel's demand to evacuate their post in Lebanon. Circa 300 Irish soldiers are not relinquishing their post. Unlike the Dutch in Srebrenica. 70 members of the platoon who were on leave before Israel's invasion wish to rejoin their unit. This is not bullshit 'breaking news' some of the big pro-Palestinian accounts push out so they can monetize your eye-balls, this is real and inspiring. Am sure the number of 300 was not done on purpose to evoke comparisons to the 300 Spartans under Leonidas, but some Spartan determination on the part of Europe would be much appreciated in halting the Israeli lunatic state https://t.co/x7QuOpn3WW
🔔 PENNSYLVANIA: You were the deciding state in the 2020 election. And by all indications, you are likely to be the same in 2024. So making a specific plan for casting your vote is critical. Absentee voting is an easy, convenient way to vote, so here are your step-by-step instructions for voting with absentee ballots. Pass it on to friends and family so you can all be prepared to cast your votes on time!
To find more details on absentee voting in your state, visit https://t.co/Hhl1cedx2M.
@Cmdr_Hadfield@SpaceX@sen We are in this interstitial moment between ‘Bows’ and ‘Deflector Shields’, so let’s us imagine the cosmic particles/waves separating and tumbling and waking as ride into the horizon
Please share this far and wide. As far and wide as you can. NIST Password Guidelines for 2024 are in the process of being updated.
This is a HUGE pet-peeve of mine (when vendors in particular are still operating like its 2017 and keep changing passwords every 60 days, STOP DOING THIS, it's outdated and has been shown to put you MORE at risk than less -- NIST explains why it does in this document, meticulously outlining user behavior**) so I'm sharing this in the hopes all of you will pass it along to your bosses.
The Special Publication series governing passwords is SP 800-63 "Digital Identity Guidelines".
The 2024 version is 800-63-4.
Here: https://t.co/oX8YEJHxXg
The companion docs are also on that link. They are 800-63A, 800-63B and 800-63C. These are different documents for different scenarios in play at your org.
The previous update was in2020.
The changes in the 2020 version from the 2017 version were numerous but one of them was that the password verification method should NO LONGER require passwords be changed at specific intervals (i.e. every 60 days) but in the following circumstances instead:
1. After a breach/compromise
2. User request
2024 repeats this and adds a bunch more guidlines but here is a screenshot of page 13 of the new 800-63-4 (note the # 4 after it) which outlines how your systems should now and moving forward, be handling passwords.
This goes for Active Directory, too. All your systems which have passwords should align with these guidelines provided there isn't another standard or framework you must adhere to which overrules this.
Most frameworks, however, have moved away from arbitrary password resets and complexity rules.
**We cybersec researchers and hackers use wordlists from breaches in a variety of different ways. Hackers use them in tooling to crack passwords whereas researchers use breach dumps to see the kinds of passwords users are creating and the psychology behind them.
Using complexity rules gets you the user psychology of:
Password1
Password2
and so on
Use phrasing instead and allow for spaces, which is important. Humans type phrases with spaces. They also mention phish-resistant methods and most vendors are on-board with MS going to be turning off all Legacy Auth next month, across all free accounts and tenancies.
I'm so excited for the new changes!
Ok I'm off my soapbox.
Share the love! Thank you!
Michael Lewis: "Each spring, the most interesting organization that no one’s ever heard of collects nominations for the most important awards that most people will never know were handed out..." https://t.co/hf3JsqQB7M