OK, this is a headscratcher. This is why we were surprised. I found it in a Wall Street Journal article today (paywall).
Bill Burr, the author of “NIST Special Publication 800-63. Appendix A.” which covers “traditional” password complexity requirements, has said that password complexity has failed in practice.
Whoa Nellie.
NIST started from scratch and the general idea of the new NIST guidelines is to use pass phrases of (suggested 25 normal characters) that change only as needed, as in a compromised account.
Turns out this NIST special publication has been formal since last month – and it’s been available in draft form for some time before that.
It is true that complex passwords with arbitrary password expiration force many users to make poor security choices. I applaud NIST for being pragmatic about this. Let’s at least get the conversation going. The real test will be how the audit and compliance world accepts these recommendations.
How weak are your user’s passwords? Are they... P@ssw0rd?
Verizon's recent Data Breach Report showed that 81% of hacking-related breaches used either stolen and/or weak passwords. Employees are the weakest link in your network security, using weak passwords and falling for phishing and social engineering attacks.
KnowBe4’s complimentary Weak Password Test (WPT) checks your Active Directory for several different types of weak password related threats.
WPT gives you a quick look at the effectiveness of your password policies and any fails so that you can take action. WPT tests against 10 types of weak password related threats for example; Weak, Duplicate, Empty, Never Expires, plus 6 more.
Here's how Weak Password Test works:
- Reports on the accounts that are affected
- Tests against 10 types of weak password related threats
- Does not show/report on the actual passwords of accounts
- Just download the install and run it
- Results in a few minutes!
This will take you 5 minutes and may give you some insights you never expected!
Download Now:
or cut & paste this link in your browser: https://info.knowbe4.com/weak-password-test
Thanks very much in advance !
Warm regards,
Stu Sjouwerman
Founder and CEO, KnowBe4, Inc.