diff options
| author | Christian Cleberg <[email protected]> | 2025-11-11 19:58:58 -0600 |
|---|---|---|
| committer | Christian Cleberg <[email protected]> | 2025-11-11 19:58:58 -0600 |
| commit | 4a48163d5b84faacfb486ecde18b2b7733d21c65 (patch) | |
| tree | 9194c05b413c739378f139945bff7d8075beb98f /content/blog/2019-12-16-password-security.org | |
| parent | 538c67956a506b459474d23a11fc6e4a9c0ae1ea (diff) | |
| download | cleberg.net-4a48163d5b84faacfb486ecde18b2b7733d21c65.tar.gz cleberg.net-4a48163d5b84faacfb486ecde18b2b7733d21c65.tar.bz2 cleberg.net-4a48163d5b84faacfb486ecde18b2b7733d21c65.zip | |
fix grammar in 2019 posts
Diffstat (limited to 'content/blog/2019-12-16-password-security.org')
| -rw-r--r-- | content/blog/2019-12-16-password-security.org | 50 |
1 files changed, 25 insertions, 25 deletions
diff --git a/content/blog/2019-12-16-password-security.org b/content/blog/2019-12-16-password-security.org index 213fd3f..f44153d 100644 --- a/content/blog/2019-12-16-password-security.org +++ b/content/blog/2019-12-16-password-security.org @@ -11,15 +11,15 @@ Information security, including passwords and identities, has become one of the most important digital highlights of the last decade. With [[https://www.usatoday.com/story/money/2018/12/28/data-breaches-2018-billions-hit-growing-number-cyberattacks/2413411002/][billions of people affected by data breaches each year]], there's a greater need to introduce strong information security systems. If you think you've been part of a breach, or you -want to check and see, you can use [[https://haveibeenpwned.com/][Have I Been Pwned]] to see if your email has -been involved in any public breaches. Remember that there's a possibility that a +want to check and see, you can use [[https://haveibeenpwned.com/][Have I Been Pwned]] to see if any public +breaches have exposed your email(s). Remember that there's a possibility that a company experienced a breach and did not report it to anyone. ** How Do I Protect Myself? The first place to start with any personal security check-up is to gather a list of all the different websites, apps, or programs that require you to have login -credentials. Optionally, once you know where your information is being stored, +credentials. Optionally, once you know where you are storing your information, you can sort the list from the most-important items such as banks or government logins to less important items such as your favorite meme site. You will want to ensure that your critical logins are secure before getting to the others. @@ -36,34 +36,34 @@ Personally, I recommend using a [[https://en.wikipedia.org/wiki/Passphrase][pass password. Instead of using a string of characters (whether random or simple), use a phrase and add in symbols and a number. For example, your vault password could be =Racing-Alphabet-Gourd-Parrot3=. Swap the symbols out for whichever -symbol you want, move the number around, and fine-tune the passphrase until you +symbol you want, move the number around, and fine-tune the pass phrase until you are confident that you can remember it whenever necessary. Once you've stored your passwords, make sure you continually check up on your account and make sure you aren't following bad password practices. Krebs on Security has a great [[https://krebsonsecurity.com/password-dos-and-donts/][blog post on password recommendations]]. Any time that a data -breach happens, make sure you check to see if you were included, and if you need -to reset any account passwords. +breach happens, make sure you check to see if the breach exposed your email, and +if you need to reset any account passwords. * Developers ** What Are the Basic Requirements? -When developing any password-protected application, there are a few basic rules -that anyone should follow even if they do not follow any official guidelines -such as NIST. The foremost practice is to require users to use passwords that -are at least 8 characters and cannot easily be guessed. This sounds extremely -simple, but it requires quite a few different strategies. First, the application -should check the potential passwords against a dictionary of insecure passwords -such =password=, =1234abc=, or =application_name=. - -Next, the application should offer guidance on the strength of passwords being -entered during enrollment. Further, NIST officially recommends *not* -implementing any composition rules that make passwords hard to remember (e.g. -passwords with letters, numbers, and special characters) and instead encouraging -the use of long pass phrases which can include spaces. It should be noted that -to be able to keep spaces within passwords, all unicode characters should be -supported, and passwords should not be truncated. +When developing any password-protected application, there are basic rules that +anyone should follow even if they do not follow any official guidelines such as +NIST. The foremost practice is to require users to use passwords that are at +least 8 characters and bad actors cannot easily guess them. This sounds simple, +but it requires different strategies. First, the application should check the +potential passwords against a dictionary of insecure passwords such =password=, +=1234abc=, or =application_name=. + +Next, the application should offer guidance on the strength of passwords you +enter during enrollment. Further, NIST officially recommends *not* implementing +any composition rules that make passwords hard to remember (e.g. passwords with +letters, numbers, and special characters) and instead encouraging the use of +long pass phrases which can include spaces. Note that to be able to keep spaces +within passwords, you should support all unicode characters, and you should not +truncate spaces. ** What Does NIST Recommend? @@ -87,17 +87,17 @@ NIST offers a lot of guidance on passwords, but I'm going to highlight just a few of the important factors: - Require passwords to be a minimum of 8 characters (6 characters if randomly - generated and be generated using an approved random bit generator). + generated and generate using an approved random bit generator). - Compare potential passwords against a list that contains values known to be commonly-used, expected, or compromised. - Offer guidance on password strength, such as a strength meter. - Implement a rate-limiting mechanism to limit the number of failed authentication attempts for each user account. -- Do not require composition rules for passwords and do not require passwords to - be changed periodically (unless compromised). +- Do not require composition rules for passwords and do not require users to + change their passwords periodically (unless compromised). - Allow pasting of user identification and passwords to facilitate the use of password managers. -- Allow users to view the password as it is being entered. +- Allow users to view the password as they type. - Use secure forms of communication and storage, including salting and hashing passwords using a one-way key derivation function. |
