- Get four Apple AirTags for just $73 with this Black Friday deal
- I tested Beats' new Pill speaker and it delivered gloriously smooth sound (and it's on sale for Black Friday)
- I tested a 'luxury' nugget ice maker, and it's totally worth it - plus it's $150 off for Black Friday
- The Dyson Airwrap is $120 off ahead of Black Friday - finally
- This 5-in-1 charging station replaced several desk accessories for me (and it's 33% off for Black Friday))
NIST Scraps Passwords Complexity and Mandatory Changes
Using a mixture of character types in your passwords and regularly changing passwords are officially no longer best password management practices according to new guidelines published by the US National Institute of Standards and Technology (NIST).
In NIST’s latest version of its Password Guidelines, the leading security standards organization suggested credential service providers (CSPs) stop recommending passwords using several character types and to stop mandating periodic password changes unless the authenticator has been compromised.
Additionally, NIST required CSPs not to use knowledge-based authentication (KBA) or security questions when choosing passwords.
These decisions formalize principles that public and private organizations like the US Federal Trade Commission and Microsoft have long recommended.
Read more: It’s Time to Take a Modern Approach to Password Management
Good Passwords Between 15-64 Characters
The latest guidelines still require passwords to be at least eight characters.
Other notable recommendations include:
- Passwords should be of a minimum of 15 characters
- CSPs should allow passwords of a maximum of at least 64 characters
- CSPs should allow ASCII and Unicode characters to be included in passwords
The new guidelines were published in September 2024 as part of NIST’s second public draft of SP 800-63-4, the latest version of its Digital Identity Guidelines.
The previous version of NIST’s Password Guidelines was published in 2020.
Read more: Five Ways to Dramatically Reduce the Risk of Password Compromise