Comments

1 point

So, how long until these US Government recommendations actually get implemented by the US Government?

The password requirements thst I constantly have to work around at work, for our Oracle server, are as follows:

  • Must change every 3 months
  • Cannot have X number of characters the same, compared to the previous password
  • Max length of 30 characters (god, but this always infuriates me)
  • At least 2 lowercase letters
  • At least 2 uppercase letters
  • At least 2 numbers
  • At least 2 symbol characters (but with a whole bunch of them, like @, considered invalid)
  • Cannot have the same character twice in a row (what possible purpose does this serve?!)

There’s probably others I can’t even remember, or haven’t encountered.

permalink
report
reply
6 points

Interesting little history piece, but I did not see any evidence that password complexity rules don’t help which i think was supposed to be the point of the article.

permalink
report
reply
1 point

The article leads with the US Government changing their recommendations on password policies, so the assumption is that they’ve done the homework. Still, yeah, I’d have been interested to see the details.

permalink
report
parent
reply
3 points

They got it wrong because they never understood how these passwords existed to begin with.

permalink
report
reply

Pulse of Truth

!pulse_of_truth@infosec.pub

Create post

Cyber Security news and links to cyber security stories that could make you go hmmm. The content is exactly as it is consumed through RSS feeds and wont be edited (except for the occasional encoding errors).

This community is automagically fed by an instance of Dittybopper.

Community stats

  • 1.2K

    Monthly active users

  • 1.1K

    Posts

  • 841

    Comments

Community moderators