OK, this is a headscratcher. This is why we were surprised. I found it in a Wall Street Journal article today (paywall).
Bill Burr, the author of “NIST Special Publication 800-63. Appendix A.” which covers “traditional” password complexity requirements, has said that password complexity has failed in practice.
NIST started from scratch and the general idea of the new NIST guidelines is to use pass phrases of (suggested 25 normal characters) that change only as needed, as in a compromised account.
Turns out this NIST special publication has been formal since last month – and it’s been available in draft form for some time before that.
It is true that complex passwords with arbitrary password expiration force many users to make poor security choices. I applaud NIST for being pragmatic about this. Let’s at least get the conversation going. The real test will be how the audit and compliance world accepts these recommendations.
So now, we need a little bit of feedback about the password policy in your organization, because we were just updating our password training module!
Please take this 1-minute, 7-question, multiple choice survey.
Help me out and give me your feedback? This is the link to Survey Monkey (not phishing, but if you do not want to click on redirected links, please copy and paste this in your browser)
How weak are your user’s passwords? Are they... P@ssw0rd?
Verizon's recent Data Breach Report showed that 81% of hacking-related breaches used either stolen and/or weak passwords. Employees are the weakest link in your network security, using weak passwords and falling for phishing and social engineering attacks.
KnowBe4’s complimentary Weak Password Test (WPT) checks your Active Directory for several different types of weak password related threats.
WPT gives you a quick look at the effectiveness of your password policies and any fails so that you can take action. WPT tests against 10 types of weak password related threats for example; Weak, Duplicate, Empty, Never Expires, plus 6 more.
Here's how Weak Password Test works:
- Reports on the accounts that are affected
- Tests against 10 types of weak password related threats
- Does not show/report on the actual passwords of accounts
- Just download the install and run it
- Results in a few minutes!
This will take you 5 minutes and may give you some insights you never expected!
or cut & paste this link in your browser: https://info.knowbe4.com/weak-password-test
Thanks very much in advance !
Founder and CEO, KnowBe4, Inc.