Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Latest Password Best Practices from the National Institute of Standards and Technology

The Latest Password Best Practices from the National Institute of Standards and Technology

Passwords are the first line of defense your accounts have against the myriad of threats out there. It’s imperative that you follow industry best practices when creating them so as to maximize security. Thankfully, the latest guidelines from the National Institute of Standards and Technology, or NIST, make creating secure passwords easy.

What is the NIST?

The NIST has been the go-to authority on password creation standards for quite some time, and while they constantly change their advised practices, it is to keep up with the endlessly-shifting nature of cybersecurity. Their most recent update to password best practices can be seen in the below guidelines.

New Guidelines

Several corporations currently use the NIST guidelines and all Federal agencies are expected to adhere to them as well. Here are the latest steps in creating a secure password.

1. Length is More Important than Complexity

Password complexity has been one of the pillars of password security for years, but these days, the guidelines disagree. NIST suggests that the longer the password, the harder it is to decrypt. In fact, according to the NIST, organizations that require new passwords to be complex with numbers, symbols, upper and lower-case letters, etc, actually make the password less secure.

There are two major reasons for this determination. The first is that users often make their passwords far too complicated and forget them, leading to the eventual addition of something like an exclamation point or a 1 at the end of the password. This doesn’t make the password much more complex. Furthermore, users might be tempted to use the same complex password for multiple accounts, which is certainly not going to help their cause.

2. Eliminate Password Resets

Most businesses require that their staff reset their passwords every so often, whether it’s every month or every few months. The strategy is supposed to ensure that even compromised passwords can only be used for so long, locking would-be hackers out after the password has been changed. NIST suggests that this practice is actually counterproductive to account security.

Their reasoning is that, if people have to set passwords up too frequently, they won’t be as careful when creating them. Furthermore, when people do change their passwords, they are more likely to use the same pattern to remember them. If a previous password has been compromised, there is a good chance that this pattern can give the attacker clues into what the current password is.

3. Don’t Hurt Security by Eliminating Ease of Use

A big concern that many network administrators have is that, if they remove options such as showing a password while the user types it in or allowing copy/paste, it is more likely that the password will be compromised. The truth is that ease of use does not compromise security; it turns out that making it easier for people to properly authenticate themselves is better for security than restricting them.

4. No More Password Hints

Some systems allow for password hints where the user can assign a question and a designated answer to access the account, should they forget the password. This system in itself is flawed and the very reason why many organizations have been hacked. Thanks to social media websites and the Internet as a whole, it’s not impossible to imagine a hacker using websites or other resources to look up information on a particular user to gain access to an account. And you know what they say; once it’s on the Internet, it’s there to stay.

5. Limit Password Attempts

Placing a limit on password attempts is beneficial for your organization’s network security in just about every circumstance imaginable. Password remembrance is usually one of two things; either the user will remember the password or they will have it stored somewhere. Locking users out of their account for a short period of time can be a great way to dissuade would-be hackers from trying to guess a user’s password.

6. Use Multi-Factor Authentication

At Total Tech Care, we like to reinforce with our clients that multi-factor or two-factor authentication is imperative for every account possible. The NIST recommends that users be able to demonstrate at least two of these three authentication measures before a successful login. They are the following:

  1. “Something you know” (like a password)
  2. “Something you have” (like a mobile device)
  3. “Something you are” (like a face or a fingerprint)

If at least two of these criteria are met, then chances are you are supposed to be on the network. Plus, consider how hard it would be for a hacker to gain access to more than one of the above. It just makes sense.

If you don’t make password security a priority for your business, you might come to regret it later, and no one wants to be the one responsible for a data breach. If you need a hand with implementing a password management system or other security best practices, reach out to us at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Sunday, 04 May 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Software Efficiency Business Google Network Security Microsoft Internet Email Malware Backup Workplace Tips Innovation Data User Tips Computer Mobile Devices Hardware IT Services Disaster Recovery Android VoIP communications Business Continuity Smartphones Communication IT Support Miscellaneous Smartphone Mobile Device Small Business Network Browser Productivity Collaboration Quick Tips Cybersecurity Business Management Users Phishing Upgrade Managed IT Services Windows Outsourced IT Data Backup Ransomware Windows 10 Data Recovery Cloud Computing Office Server Save Money Passwords Windows 10 Virtualization Gadgets Saving Money Holiday Social Media Tech Term Chrome Managed IT Services Managed Service Automation Microsoft Office Computers Artificial Intelligence Facebook Operating System Cybercrime Internet of Things BYOD Wi-Fi Mobile Device Management Networking IT Support Hacking Health Covid-19 Spam Alert Office 365 Telephone Systems Information Information Technology Remote Managed Service Provider BDR Bandwidth Employer-Employee Relationship Recovery Social Engineering Mobility Router Law Enforcement Remote Monitoring Mobile Computing Application Password App History Money Encryption Data Breach Applications Big Data Human Resources How To Private Cloud Mobile Office Managed IT Blockchain Paperless Office Data Storage Patch Management Office Tips Apps Training VPN Government Remote Computing Flexibility Mouse Marketing HaaS WiFi IT solutions Entertainment Website Budget Bring Your Own Device Data Management Work/Life Balance Vulnerability Wireless Windows 7 Word Infrastructure Voice over Internet Protocol Gmail Servers Settings Google Drive Two-factor Authentication Avoiding Downtime Data Security Social User Error Employee/Employer Relationship Meetings Save Time RMM USB Telephone System Staff Software as a Service Cleaning Risk Management Machine Learning Hacker Conferencing Remote Work Connectivity Scam The Internet of Things Lithium-ion battery End of Support Education Physical Security Safety Vendor Management Sports HIPAA Redundancy Firewall Keyboard Vendor Data Protection Virtual Reality Apple Managed Services Display Comparison Samsung Network Congestion Computer Accessories Processor eWaste CES Value Document Management Solid State Drive Hard Drive Wireless Technology Electronic Medical Records How to Business Technology Downtime Content Management Spam Blocking Printer Access Control Wearable Technology Bluetooth Hiring/Firing Retail Virtual Assistant Hard Drives Computing Data storage Automobile Instant Messaging Authentication Robot Excel Biometrics Computing Infrastructure Virtual Desktop Going Green IT Consultant Digital Signage Update Business Intelligence Humor DDoS Worker Battery Audit Google Docs Shadow IT IT Management Identity Theft SharePoint Legal Procurement Workplace Strategy Botnet Net Neutrality Internet Exlporer IT Plan Customer Service Help Desk Augmented Reality Environment Printing Unsupported Software Fraud PDF Fax Server Charger Remote Worker Managed Services Provider Proactive IT Compliance Cryptocurrency SaaS OneNote Computer Care Virus Database Best Practice YouTube Current Events Remote Workers Unified Threat Management Black Market Telephony Manufacturing Root Cause Analysis Email Best Practices Business Owner GDPR Bloatware IT Assessment Hosted Computing Wireless Internet NarrowBand HBO Online Shopping Knowledge Managing Stress Music Computer Tips Search File Sharing Tablets Managed IT Service Skype Security Cameras Biometric Security Data loss Specifications Virtual CIO Camera Entrepreneur OneDrive Cameras iPhone Inventory Peripheral Wire Outlook Evernote Leadership Troubleshooting Shortcut Digital Security Cameras Using Data Start Menu Travel 5G Screen Mirroring Millennials Loyalty Printers Cost Management Copiers Files Social Networking Quick Tip Smart Office Chromecast Frequently Asked Questions Wireless Charging Books Ergonomics Mobile Smartwatch Windows 10s OLED Uninterrupted Power Supply Cast Workforce Virtual Private Network Development Printer Server Colocation PCI DSS Virtual Machine Tip of the week Cables webinar Running Cable Emergency Employer Employee Relationship 2FA Memory Fiber Optics Monitor Professional Services Employee Public Cloud Cabling Telecommuting Assessment Project Management Messaging Nanotechnology Policy Hypervisor Windows Server 2008 Cortana Dark mode Trend Micro Reputation Tools Digital Signature Streaming Media Default App Tech Support Television Content Warranty SMS Procedure Techology HVAC Science Saving Time Laptop Google Apps dark theme Shopping Customers Analysis Google Search Devices IT Infrastructure Public Computer Audiobook Administrator AI Customer Relationship Management FinTech Enterprise Content Management Touchpad Regulations Bing Distributed Denial of Service Transportation Rootkit Consultant MSP Analyitcs Social Network Accountants Computer Fan Thought Leadership Investment Credit Cards Politics Microchip Programming Analytics Advertising Employees Password Management Employee/Employer Relationships Password Manager Workers Benefits FENG Multi-Factor Security Windows 365 Best Available ISP Notifications Twitter ROI IBM Antivirus WIndows 7 Search Engine Video Conferencing Smart Technology Sales NIST Windows 8 Bitcoin Flash Business Mangement Shortcuts Trending IT service Point of Sale Personal Relocation Smart Tech Cryptomining Addiction Software Tips Amazon Supercomputer Supply Chain Management Monitoring Video Games Tablet Batteries Sync Recycling Emails Domains Windows 8.1 Worker Commute Wiring Digitize Practices PowerPoint Cache Windows Server 2008 R2 Windows Media Player Amazon Web Services User Experience Two Factor Authentication Maintenance Customer relationships Scalability Safe Mode Criminal Netflix IaaS

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code