ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    The NIST Finally Formally Chooses SAM Security Model for Passwords

    News
    nist security
    6
    14
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by scottalanmiller

      Not to say I told you so but... had people listened to me years ago we could have saved a lot of tax payer dollars here 🙂 Recently the US NIST has formalized their recommendations for practical password security and, no surprise, it mirrors when I've been recommending and saying was IT security standard practice for years - long non-complex passphrases that are easy for humans to remember but hard for computers to brute force that only change very infrequently to give humans more chance of remembering them and avoiding anything that causes humans to work around security systems. Yup, simple, common sense security that pragmatically matches how humans actually function and takes into account how computers actually need to attack passphrases.

      The important takeaway from the NIST decisions is... simple user education and good IT policies are the best approach. Don't try to shove changes down your users' throats, don't try to be the authority, help them choose good passphrases and don't make them work around you.

      https://imgs.xkcd.com/comics/password_strength.png

      1 Reply Last reply Reply Quote 4
      • scottalanmillerS
        scottalanmiller
        last edited by

        Buried in here, I'm told, lol, for those that want to dig it out: https://pages.nist.gov/800-63-3/sp800-63b.html

        1 Reply Last reply Reply Quote 0
        • stacksofplatesS
          stacksofplates
          last edited by

          0_1502147552416_pass.png

          1 Reply Last reply Reply Quote 2
          • DashrenderD
            Dashrender
            last edited by

            Could have sworn I posted about this weeks ago. 😉

            JaredBuschJ 1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @Dashrender
              last edited by

              @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

              Could have sworn I posted about this weeks ago. 😉

              You did, but you didn't claim that NIST followed your recommendation.

              scottalanmillerS 1 Reply Last reply Reply Quote 2
              • scottalanmillerS
                scottalanmiller @JaredBusch
                last edited by

                @jaredbusch said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                Could have sworn I posted about this weeks ago. 😉

                You did, but you didn't claim that NIST followed your recommendation.

                I only said that they mirrored it, not followed it. Not quite the same.

                1 Reply Last reply Reply Quote 0
                • gjacobseG
                  gjacobse
                  last edited by

                  just found this:

                  Man who came up with rules for creating passwords says he blew it

                  DashrenderD 1 Reply Last reply Reply Quote 2
                  • DashrenderD
                    Dashrender @gjacobse
                    last edited by

                    @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                    just found this:

                    Man who came up with rules for creating passwords says he blew it

                    During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

                    WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

                    DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
                    • DustinB3403D
                      DustinB3403 @Dashrender
                      last edited by

                      @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                      @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                      just found this:

                      Man who came up with rules for creating passwords says he blew it

                      During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

                      WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

                      Because he was fucking paid to write the memo. Do what you're told or find a new job.

                      Obviously.

                      DashrenderD 1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @DustinB3403
                        last edited by

                        @dustinb3403 said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                        @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                        @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                        just found this:

                        Man who came up with rules for creating passwords says he blew it

                        During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

                        WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

                        Because he was fucking paid to write the memo. Do what you're told or find a new job.

                        Obviously.

                        Yeah - more govment meaningless crap! 🙂

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @Dashrender
                          last edited by

                          @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                          @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                          just found this:

                          Man who came up with rules for creating passwords says he blew it

                          During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

                          WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

                          We all knew whoever did it didn't know the first thing about passwords. But why the NIST let him make it... that's the real question.

                          DustinB3403D DashrenderD 2 Replies Last reply Reply Quote 1
                          • DustinB3403D
                            DustinB3403 @scottalanmiller
                            last edited by

                            @scottalanmiller is that really the question.

                            More importantly why does it fucking matter. It was written so long ago and there has been plenty of time and evidence that what was written down was complete bullshit.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • DashrenderD
                              Dashrender @scottalanmiller
                              last edited by

                              @scottalanmiller said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                              @dashrender said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                              @gjacobse said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                              just found this:

                              Man who came up with rules for creating passwords says he blew it

                              During the interview, Burr also admitted that he didn't know much about how passwords worked when he created the memo.

                              WTF are you doing making a memo then? Not that we probably really understood the potential issues at that point, but still.

                              We all knew whoever did it didn't know the first thing about passwords. But why the NIST let him make it... that's the real question.

                              this was my real question...

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @DustinB3403
                                last edited by

                                @dustinb3403 said in The NIST Finally Formally Chooses SAM Security Model for Passwords:

                                @scottalanmiller is that really the question.

                                More importantly why does it fucking matter. It was written so long ago and there has been plenty of time and evidence that what was written down was complete bullshit.

                                Except they new it was BS in 2003, too.

                                1 Reply Last reply Reply Quote 2
                                • 1 / 1
                                • First post
                                  Last post