Home / Companies / Socket / Blog / Post Details
Content Deep Dive

NIST’s New Password Guidelines Will Eliminate Periodic Chang...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
660
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

NIST (National Institute of Standards and Technology) is updating its Digital Identity Guidelines to improve authentication practices by eliminating the requirements for periodic password changes and the use of special characters, instead emphasizing longer and more complex passwords. The new guidelines, aimed at enhancing security for Federal Information Systems, suggest minimum password lengths of eight to fifteen characters and recommend accepting a wider range of characters, including Unicode. They also discourage composition rules that mandate mixing character types, as well as periodic password changes, unless there is evidence of compromise. The guidelines emphasize user-friendliness and security by supporting password managers, allowing password visibility for verification, and using encryption for secure handling. The proposed changes aim to guide users in creating strong passwords and encourage secure practices among verifiers and Credential Service Providers (CSPs). After the public comment period ends, NIST will incorporate feedback into a revised version of the guidelines, although no specific timeline for the final publication is provided.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.