Nemeski@lemm.ee to Cybersecurity@sh.itjust.worksEnglish · vor 2 MonatenNIST proposes barring some of the most nonsensical password rulesarstechnica.comexternal-linkmessage-square8fedilinkarrow-up191arrow-down10cross-posted to: cybersecurity@sh.itjust.workstechnology@lemmy.world
arrow-up191arrow-down1external-linkNIST proposes barring some of the most nonsensical password rulesarstechnica.comNemeski@lemm.ee to Cybersecurity@sh.itjust.worksEnglish · vor 2 Monatenmessage-square8fedilinkcross-posted to: cybersecurity@sh.itjust.workstechnology@lemmy.world
minus-squareUID_Zero@infosec.publinkfedilinkEnglisharrow-up8arrow-down1·vor 2 MonatenPlease don’t take those recommendations out of context. They also recommend MFA, but people only ever bring up the “no rotation” bit.
minus-squareZorsith@lemmy.blahaj.zonelinkfedilinkEnglisharrow-up5·vor 2 MonatenAre they at least recommending non-SMS MFA now?
minus-squarelinearchaos@lemmy.worldlinkfedilinkEnglisharrow-up4·vor 2 MonatenEmphasis was from the article, not mine. They also recommend not using knowledge based prompts, allowing at least 64: characters,
Please don’t take those recommendations out of context.
They also recommend MFA, but people only ever bring up the “no rotation” bit.
Are they at least recommending non-SMS MFA now?
Emphasis was from the article, not mine.
They also recommend not using knowledge based prompts, allowing at least 64: characters,