Comment on NIST proposes barring some of the most nonsensical password rules

<- View Parent
NotMyOldRedditName@lemmy.world ⁨1⁩ ⁨day⁩ ago

But they mess that up with their 8 char rule

Verifiers and CSPs SHALL require passwords to be a minimum of eight characters in length and SHOULD require passwords to be a minimum of 15 characters in length.

I’d they’d just said shall require 15 but not require special chars then that’s okay, but they didn’t.

Then you end up with the typical shitty manager who sees this, and says they recommend 8 and no special chars, and that’s what it becomes.

source
Sort:hotnewtop