As imperfect a means of authentication as they are, “memorized secrets” like passwords, pass phrases and PINs are common, and indeed are the primary means of authentication for most computer systems. In June, the National Institute of Standards and Technology issued a new publication on digital identity management that, in part, recommends changes to password policy that has become standard in many organizations—policy requiring passwords with special characters.
Here is what the NIST says:
Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and may be entirely numeric. If the CSP or verifier disallows a chosen memorized secret based on its appearance on a blacklist compromised values, the subscriber SHALL be required to choose a different memorized secret. No other complexity requirements for memorized secrets SHOULD be imposed.
The NIST believes that the complexity derived from special characters is of limited benefit to security, yet creates (well known) usability problems and promotes “counterproductive” user behaviour—writing passwords down or storing them electronically in plain text. It’s better, according to the NIST, to allow for long passwords (that may incorporate spaces) and use other protective measures such as password blacklists, secure hashed password storage and limits to the number of failed authentication attempts.
The NIST publication includes other related guidance, including a recommendation against routine password resetting.
NIST Special Publication 800-63B – Digital Identity Guidelines (June 2017)
By Dan Michaluk, All About Information
Latest posts by Occasional Contributors (see all)
- Finance is doing a consultation on whether to increase the disbursement quota for Canadian registered charities - September 27, 2021
- Many charities with March 31 year ends need to file their T3010 by September 30 - September 13, 2021
- Reminder from Corporations Canada re: AGMs in 2021 for CNCA corporations - September 1, 2021