Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Latest Password Best Practices from the National Institute of Standards and Technology

The Latest Password Best Practices from the National Institute of Standards and Technology

Passwords are the first line of defense your accounts have against the myriad of threats out there. It’s imperative that you follow industry best practices when creating them so as to maximize security. Thankfully, the latest guidelines from the National Institute of Standards and Technology, or NIST, make creating secure passwords easy.

What is the NIST?

The NIST has been the go-to authority on password creation standards for quite some time, and while they constantly change their advised practices, it is to keep up with the endlessly-shifting nature of cybersecurity. Their most recent update to password best practices can be seen in the below guidelines.

New Guidelines

Several corporations currently use the NIST guidelines and all Federal agencies are expected to adhere to them as well. Here are the latest steps in creating a secure password.

1. Length is More Important than Complexity

Password complexity has been one of the pillars of password security for years, but these days, the guidelines disagree. NIST suggests that the longer the password, the harder it is to decrypt. In fact, according to the NIST, organizations that require new passwords to be complex with numbers, symbols, upper and lower-case letters, etc, actually make the password less secure.

There are two major reasons for this determination. The first is that users often make their passwords far too complicated and forget them, leading to the eventual addition of something like an exclamation point or a 1 at the end of the password. This doesn’t make the password much more complex. Furthermore, users might be tempted to use the same complex password for multiple accounts, which is certainly not going to help their cause.

2. Eliminate Password Resets

Most businesses require that their staff reset their passwords every so often, whether it’s every month or every few months. The strategy is supposed to ensure that even compromised passwords can only be used for so long, locking would-be hackers out after the password has been changed. NIST suggests that this practice is actually counterproductive to account security.

Their reasoning is that, if people have to set passwords up too frequently, they won’t be as careful when creating them. Furthermore, when people do change their passwords, they are more likely to use the same pattern to remember them. If a previous password has been compromised, there is a good chance that this pattern can give the attacker clues into what the current password is.

3. Don’t Hurt Security by Eliminating Ease of Use

A big concern that many network administrators have is that, if they remove options such as showing a password while the user types it in or allowing copy/paste, it is more likely that the password will be compromised. The truth is that ease of use does not compromise security; it turns out that making it easier for people to properly authenticate themselves is better for security than restricting them.

4. No More Password Hints

Some systems allow for password hints where the user can assign a question and a designated answer to access the account, should they forget the password. This system in itself is flawed and the very reason why many organizations have been hacked. Thanks to social media websites and the Internet as a whole, it’s not impossible to imagine a hacker using websites or other resources to look up information on a particular user to gain access to an account. And you know what they say; once it’s on the Internet, it’s there to stay.

5. Limit Password Attempts

Placing a limit on password attempts is beneficial for your organization’s network security in just about every circumstance imaginable. Password remembrance is usually one of two things; either the user will remember the password or they will have it stored somewhere. Locking users out of their account for a short period of time can be a great way to dissuade would-be hackers from trying to guess a user’s password.

6. Use Multi-Factor Authentication

At Total Tech Care, we like to reinforce with our clients that multi-factor or two-factor authentication is imperative for every account possible. The NIST recommends that users be able to demonstrate at least two of these three authentication measures before a successful login. They are the following:

  1. “Something you know” (like a password)
  2. “Something you have” (like a mobile device)
  3. “Something you are” (like a face or a fingerprint)

If at least two of these criteria are met, then chances are you are supposed to be on the network. Plus, consider how hard it would be for a hacker to gain access to more than one of the above. It just makes sense.

If you don’t make password security a priority for your business, you might come to regret it later, and no one wants to be the one responsible for a data breach. If you need a hand with implementing a password management system or other security best practices, reach out to us at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Wednesday, 02 April 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Software Efficiency Network Security Business Google Microsoft Internet Email Malware Backup Workplace Tips Innovation User Tips Data Computer Mobile Devices Hardware IT Services Android Disaster Recovery VoIP communications Business Continuity Smartphones Communication IT Support Miscellaneous Smartphone Mobile Device Browser Small Business Network Productivity Collaboration Quick Tips Cybersecurity Users Business Management Windows Phishing Upgrade Managed IT Services Ransomware Data Backup Outsourced IT Windows 10 Data Recovery Office Cloud Computing Server Save Money Windows 10 Passwords Virtualization Gadgets Saving Money Holiday Tech Term Social Media Chrome Managed IT Services Managed Service Automation Microsoft Office Cybercrime Computers Artificial Intelligence Facebook Operating System Health Internet of Things BYOD Mobile Device Management Wi-Fi Networking IT Support Hacking Remote Spam Alert Covid-19 Information Office 365 Telephone Systems Managed Service Provider Information Technology Recovery Employer-Employee Relationship Router BDR Bandwidth Social Engineering Mobility Human Resources Law Enforcement Mobile Computing Remote Monitoring Application Password Money App History Encryption Big Data Applications Data Breach Government Remote Computing Blockchain Private Cloud Paperless Office Mobile Office How To Managed IT Apps Office Tips Data Storage Patch Management Training VPN Servers Flexibility Marketing Two-factor Authentication Avoiding Downtime WiFi IT solutions Data Security Entertainment Mouse Website HaaS Budget Bring Your Own Device Data Management Work/Life Balance Infrastructure Voice over Internet Protocol Wireless Vulnerability Windows 7 Word Gmail Google Drive Settings Firewall Keyboard Vendor Management Virtual Reality Apple Vendor Social Managed Services Software as a Service Display Telephone System Staff USB User Error Save Time Machine Learning Meetings Connectivity Remote Work Employee/Employer Relationship Cleaning RMM Risk Management Hacker Conferencing End of Support The Internet of Things Physical Security Lithium-ion battery Scam Education Safety Data Protection HIPAA Sports Redundancy Comparison Net Neutrality Workplace Strategy Unified Threat Management Fax Server Proactive IT Help Desk Computer Accessories Unsupported Software CES Printing Best Practice SaaS YouTube Charger Business Technology Black Market Content Management Access Control Compliance OneNote Computer Care Managed Services Provider Printer Network Congestion Virtual Assistant Current Events Authentication Database Bluetooth eWaste Document Management Telephony Solid State Drive Wireless Technology Samsung How to Downtime Remote Workers Value Processor Update Data storage Spam Blocking Electronic Medical Records IT Consultant Wearable Technology Automobile Retail Hard Drives Hard Drive Google Docs Instant Messaging Robot Computing Infrastructure Excel Hiring/Firing Identity Theft Humor Going Green Biometrics Computing Virtual Desktop Battery Augmented Reality DDoS Shadow IT Fraud Legal Business Intelligence Digital Signage SharePoint Remote Worker Audit Internet Exlporer Worker IT Management Cryptocurrency Botnet Customer Service PDF Virus IT Plan Environment Procurement Windows Media Player Relocation Workers Hosted Computing Social Network Benefits User PowerPoint Antivirus GDPR FENG Wireless Internet Windows 8 Online Shopping Investment IT service Video Games File Sharing Employees IBM Employee/Employer Relationships Inventory Smart Technology Specifications ISP Managing Stress Worker Commute Flash Camera Windows 365 Experience Wire Video Conferencing Tablet Evernote ROI Travel Shortcuts Cameras Domains Scalability Software Tips Sales Supercomputer Bitcoin Emails Personal Millennials Cryptomining Business Owner Sync Printers Point of Sale IaaS Maintenance Smart Office Supply Chain Management NarrowBand Wireless Charging Search Monitoring Bloatware Batteries iPhone Netflix Digitize Two Factor Authentication Workforce Virtual Private Network Windows 8.1 Root Cause Analysis Tablets Cables Windows Server 2008 R2 Music Printer Server HBO Customer relationships Entrepreneur Knowledge Files Nanotechnology IT Assessment Telecommuting Manufacturing Skype Project Management Email Best Practices Shortcut Data loss Chromecast Cortana Troubleshooting Security Cameras Outlook Computer Tips Cost Management Leadership Digital Signature Managed IT Service Social Networking Colocation OneDrive Uninterrupted Power Supply Biometric Security Start Menu Warranty Virtual CIO Screen Mirroring HVAC Peripheral Loyalty Google Apps Books Frequently Asked Questions Digital Security Cameras Monitor Analysis Using Data Windows 10s Devices Copiers 5G Running Cable Mobile Administrator Cast Enterprise Content Management Quick Tip Memory Streaming Media Emergency Smartwatch Tip of the week MSP Ergonomics Reputation webinar Accountants Public Cloud Thought Leadership Development Tech Support Employer Employee Relationship Credit Cards OLED Content Professional Services Microchip Consultant Techology Password Management PCI DSS Laptop Assessment Password Manager Virtual Machine Multi-Factor Security Employee Analytics Windows Server 2008 2FA Customers Fiber Optics Audiobook Tools Search Engine Twitter Messaging Science Cabling Best Available NIST Policy Touchpad Television Business Mangement Hypervisor Smart Tech Trend Micro Trending WIndows 7 Dark mode Distributed Denial of Service Politics Customer Relationship Management Advertising Addiction SMS Amazon Default App Procedure Analyitcs Public Computer Recycling Saving Time Programming Practices Shopping Notifications Transportation Google Search Regulations Wiring dark theme Computer Fan Cache AI Rootkit Amazon Web Services IT Infrastructure Bing Safe Mode FinTech Criminal

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code