Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

The Latest Password Best Practices from the National Institute of Standards and Technology

The Latest Password Best Practices from the National Institute of Standards and Technology

Passwords are the first line of defense your accounts have against the myriad of threats out there. It’s imperative that you follow industry best practices when creating them so as to maximize security. Thankfully, the latest guidelines from the National Institute of Standards and Technology, or NIST, make creating secure passwords easy.

What is the NIST?

The NIST has been the go-to authority on password creation standards for quite some time, and while they constantly change their advised practices, it is to keep up with the endlessly-shifting nature of cybersecurity. Their most recent update to password best practices can be seen in the below guidelines.

New Guidelines

Several corporations currently use the NIST guidelines and all Federal agencies are expected to adhere to them as well. Here are the latest steps in creating a secure password.

1. Length is More Important than Complexity

Password complexity has been one of the pillars of password security for years, but these days, the guidelines disagree. NIST suggests that the longer the password, the harder it is to decrypt. In fact, according to the NIST, organizations that require new passwords to be complex with numbers, symbols, upper and lower-case letters, etc, actually make the password less secure.

There are two major reasons for this determination. The first is that users often make their passwords far too complicated and forget them, leading to the eventual addition of something like an exclamation point or a 1 at the end of the password. This doesn’t make the password much more complex. Furthermore, users might be tempted to use the same complex password for multiple accounts, which is certainly not going to help their cause.

2. Eliminate Password Resets

Most businesses require that their staff reset their passwords every so often, whether it’s every month or every few months. The strategy is supposed to ensure that even compromised passwords can only be used for so long, locking would-be hackers out after the password has been changed. NIST suggests that this practice is actually counterproductive to account security.

Their reasoning is that, if people have to set passwords up too frequently, they won’t be as careful when creating them. Furthermore, when people do change their passwords, they are more likely to use the same pattern to remember them. If a previous password has been compromised, there is a good chance that this pattern can give the attacker clues into what the current password is.

3. Don’t Hurt Security by Eliminating Ease of Use

A big concern that many network administrators have is that, if they remove options such as showing a password while the user types it in or allowing copy/paste, it is more likely that the password will be compromised. The truth is that ease of use does not compromise security; it turns out that making it easier for people to properly authenticate themselves is better for security than restricting them.

4. No More Password Hints

Some systems allow for password hints where the user can assign a question and a designated answer to access the account, should they forget the password. This system in itself is flawed and the very reason why many organizations have been hacked. Thanks to social media websites and the Internet as a whole, it’s not impossible to imagine a hacker using websites or other resources to look up information on a particular user to gain access to an account. And you know what they say; once it’s on the Internet, it’s there to stay.

5. Limit Password Attempts

Placing a limit on password attempts is beneficial for your organization’s network security in just about every circumstance imaginable. Password remembrance is usually one of two things; either the user will remember the password or they will have it stored somewhere. Locking users out of their account for a short period of time can be a great way to dissuade would-be hackers from trying to guess a user’s password.

6. Use Multi-Factor Authentication

At Total Tech Care, we like to reinforce with our clients that multi-factor or two-factor authentication is imperative for every account possible. The NIST recommends that users be able to demonstrate at least two of these three authentication measures before a successful login. They are the following:

  1. “Something you know” (like a password)
  2. “Something you have” (like a mobile device)
  3. “Something you are” (like a face or a fingerprint)

If at least two of these criteria are met, then chances are you are supposed to be on the network. Plus, consider how hard it would be for a hacker to gain access to more than one of the above. It just makes sense.

If you don’t make password security a priority for your business, you might come to regret it later, and no one wants to be the one responsible for a data breach. If you need a hand with implementing a password management system or other security best practices, reach out to us at 866-348-2602.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Thursday, 21 November 2024
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Business Google Network Security Microsoft Internet Email Malware Backup Workplace Tips Innovation User Tips Data Computer Mobile Devices Hardware IT Services Android VoIP Disaster Recovery communications IT Support Business Continuity Smartphones Communication Smartphone Miscellaneous Mobile Device Small Business Network Browser Productivity Collaboration Quick Tips Cybersecurity Business Management Users Managed IT Services Windows Upgrade Phishing Data Backup Outsourced IT Ransomware Windows 10 Data Recovery Office Server Save Money Cloud Computing Windows 10 Passwords Gadgets Saving Money Holiday Tech Term Chrome Social Media Virtualization Managed IT Services Managed Service Microsoft Office Automation Computers Cybercrime Artificial Intelligence Operating System Facebook Health Internet of Things BYOD Mobile Device Management Wi-Fi Networking IT Support Hacking Covid-19 Information Alert Spam Office 365 Managed Service Provider Telephone Systems Information Technology Remote BDR Bandwidth Social Engineering Mobility Router Recovery Employer-Employee Relationship Law Enforcement Mobile Computing Human Resources Data Breach Application Remote Monitoring Password Money App Encryption Big Data History Applications Blockchain Paperless Office Private Cloud Remote Computing Managed IT Mobile Office Apps How To Office Tips Training VPN Data Storage Government Patch Management Windows 7 WiFi Word Two-factor Authentication IT solutions Entertainment Website Budget Servers Mouse HaaS Bring Your Own Device Infrastructure Data Management Work/Life Balance Voice over Internet Protocol Data Security Wireless Google Drive Gmail Flexibility Settings Marketing Vulnerability Avoiding Downtime Vendor Scam Managed Services Telephone System Virtual Reality Display Staff Software as a Service Apple Machine Learning Save Time USB Vendor Management Remote Work Social Connectivity Employee/Employer Relationship User Error RMM Meetings Cleaning Risk Management End of Support Hacker Education Physical Security Data Protection Safety The Internet of Things HIPAA Lithium-ion battery Sports Redundancy Keyboard Conferencing Firewall Virtual Assistant Worker Database Audit Authentication IT Management Printer SaaS Remote Workers Document Management Bluetooth Wireless Technology Botnet Solid State Drive Processor IT Plan How to Downtime Network Congestion Update eWaste Hard Drive Unsupported Software Data storage Automobile IT Consultant Google Docs Charger Identity Theft Humor Computing Computing Infrastructure Compliance Computer Care Going Green Wearable Technology OneNote Retail Hard Drives Current Events Telephony Augmented Reality Instant Messaging Excel Samsung Fraud Robot Battery Remote Worker Biometrics Digital Signage Shadow IT Value Virtual Desktop Legal Cryptocurrency Spam Blocking Electronic Medical Records Internet Exlporer DDoS Procurement Workplace Strategy SharePoint Net Neutrality PDF Hiring/Firing Comparison Virus Help Desk CES Proactive IT Unified Threat Management Printing Computer Accessories Customer Service Business Technology Environment Content Management Best Practice YouTube Access Control Managed Services Provider Business Intelligence Black Market Fax Server Monitoring IT service Batteries Business Owner NarrowBand Workforce Windows 8.1 Digitize Virtual Private Network Windows Server 2008 R2 Search Tablet Public Computer Cables Customer relationships Domains Regulations iPhone Transportation Rootkit Telecommuting Email Best Practices IT Assessment Project Management Manufacturing Computer Fan Nanotechnology Maintenance Cortana Printer Server IaaS Computer Tips Managed IT Service Bloatware Security Cameras Workers Files Digital Signature Benefits Chromecast Virtual CIO OneDrive Warranty Biometric Security FENG HVAC Tablets IBM Google Apps Peripheral Digital Security Cameras Using Data Flash Entrepreneur Colocation Analysis Smart Technology Uninterrupted Power Supply Copiers Administrator 5G Devices Shortcut Software Tips Enterprise Content Management Supercomputer Monitor Quick Tip Ergonomics Sync MSP Cost Management Smartwatch Emails Accountants Credit Cards Development Microchip Social Networking OLED Thought Leadership Virtual Machine Password Management Reputation Password Manager Streaming Media PCI DSS 2FA Fiber Optics Content Employee Netflix Two Factor Authentication Tech Support Multi-Factor Security Laptop Consultant Running Cable Messaging Search Engine Cabling Root Cause Analysis Techology Twitter Hypervisor HBO NIST Memory Knowledge Customers Business Mangement Music Analytics Policy Dark mode Trend Micro Skype Audiobook Smart Tech Trending Touchpad Amazon Best Available SMS Default App Data loss Addiction Saving Time Outlook Leadership Recycling WIndows 7 Troubleshooting Procedure dark theme Shopping Start Menu Politics Wiring Google Search Advertising Practices Science Loyalty Amazon Web Services AI IT Infrastructure Screen Mirroring Cache Frequently Asked Questions Safe Mode Bing Criminal Books Notifications FinTech Social Network Mobile GDPR Windows 10s Hosted Computing Cast Wireless Internet Online Shopping Distributed Denial of Service Customer Relationship Management Investment Employees Windows Media Player Employee/Employer Relationships Tip of the week File Sharing Analyitcs webinar Relocation User Emergency PowerPoint Employer Employee Relationship Specifications Windows 365 Professional Services Camera Programming ISP Public Cloud Inventory ROI Video Games Wire Assessment Evernote Video Conferencing Sales Bitcoin Windows Server 2008 Worker Commute Shortcuts Managing Stress Travel Millennials Point of Sale Antivirus Personal Tools Experience Printers Cryptomining Scalability Smart Office Windows 8 Television Wireless Charging Cameras Supply Chain Management

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code