top | item 20080709

(no title)

Artemis2 | 6 years ago

These “baseline rules” come from NIST SP 800-63B, Appendix A, which is a surprisingly digestible document: https://pages.nist.gov/800-63-3/sp800-63b.html#appA

discuss

order

Jaruzel|6 years ago

And the UK equivalent from the National Cyber Security Council is at:

https://www.ncsc.gov.uk/collection/passwords/updating-your-a...

Fun anecdote... I spent 6 months last year designing and implementing a 'Self-Service' password reset portal system and password synchronisation system for 50k+ users in a large organisation, only for the organisation in question to switch to non-expiring passwords 1 week before deployment.

Needless to say... usage of the system post deployment was almost non-existent.

Ah well, at least I still got paid.