Comment on NIST proposes barring some of the most nonsensical password rules

<- View Parent
dual_sport_dork@lemmy.world ⁨1⁩ ⁨day⁩ ago

Don’t bug users to change passwords periodically. Only do it if there’s evidence of compromise.

This is a big one. Especially in corporate environments where most of the users are, shall we say, not tech savvy. Forcing people to comply with byzantine incomprehensible password composition rules plus insisting that they change their password to a new inscrutable string that looks like somebody sneezed in punctuation marks accomplishes nothing other than enticing everyone to just write their password down on a Post-It and stick it to their monitor or under their keyboard.

Remember: Users do not care about passwords. From the perspective of anyone who isn’t a programmer or a security expert, passwords are just yet another exasperating roadblock some nerd put in front of the user that is preventing them from doing whatever it is they were actually trying to do.

source
Sort:hotnewtop