NIST’s New Password Guidelines Will Eliminate Periodic Chang...
Blog post from Socket
NIST (National Institute of Standards and Technology) is updating its Digital Identity Guidelines to improve authentication practices by eliminating the requirements for periodic password changes and the use of special characters, instead emphasizing longer and more complex passwords. The new guidelines, aimed at enhancing security for Federal Information Systems, suggest minimum password lengths of eight to fifteen characters and recommend accepting a wider range of characters, including Unicode. They also discourage composition rules that mandate mixing character types, as well as periodic password changes, unless there is evidence of compromise. The guidelines emphasize user-friendliness and security by supporting password managers, allowing password visibility for verification, and using encryption for secure handling. The proposed changes aim to guide users in creating strong passwords and encourage secure practices among verifiers and Credential Service Providers (CSPs). After the public comment period ends, NIST will incorporate feedback into a revised version of the guidelines, although no specific timeline for the final publication is provided.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.