{"id":14335,"date":"2024-11-04T12:15:40","date_gmt":"2024-11-04T06:15:40","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=14335"},"modified":"2024-11-04T12:16:15","modified_gmt":"2024-11-04T06:16:15","slug":"nist-guidelines-why-its-time-to-rethink-passwords","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/nist-guidelines-why-its-time-to-rethink-passwords\/","title":{"rendered":"NIST Guidelines: Why it&#8217;s time to rethink passwords"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-14336 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2024\/11\/13297241720821794700.jpeg\" alt=\"\" width=\"500\" height=\"261\" \/><\/p>\n<p>The landscape of password management is evolving rapidly. Recent guidance from the National Institute of Standards and Technology (NIST) is challenging outdated norms, such as frequent password changes and complex requirements that were once seen as essential to security.<\/p>\n<p>While these updates mark progress, SSH Communications Security believes it\u2019s time to take an even bolder step: moving beyond passwords entirely.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Shifting Perspectives on Password Security<\/strong><\/p>\n<p>NIST\u2019s updated guidelines reflect a reimagined approach to password security. For example, they now recommend a minimum password length of 8 characters (with support up to 64 characters) and suggest eliminating periodic changes unless there\u2019s evidence of compromise. They also discourage using security questions and hints, opting for stronger verification methods, and endorse password managers to handle complex passwords more efficiently.<\/p>\n<p>Although these changes improve the security landscape, we believe there\u2019s an even better way forward\u2014one that doesn\u2019t rely on passwords at all.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Key Recommendations in NIST\u2019s Guidance<\/strong><\/p>\n<p>NIST\u2019s guidance includes the following recommendations:<\/p>\n<ul>\n<li>Minimum password length of 8 characters, with a preference for 15 characters or more.<\/li>\n<li>Allowing up to 64 characters in password length.<\/li>\n<li>Accepting a broad range of characters, including all printing ASCII characters, spaces, and even Unicode characters.<\/li>\n<li>Avoiding composition rules, like mixing character types, that add complexity without significantly boosting security.<\/li>\n<li>Removing the need for periodic password changes, unless a compromise is suspected.<\/li>\n<li>Prohibiting the use of hints accessible to unauthenticated users.<\/li>\n<li>Avoiding knowledge-based questions, such as \u201cWhat\u2019s your mother\u2019s maiden name?\u201d<\/li>\n<li>Ensuring that the full password is verified without truncation.<\/li>\n<\/ul>\n<p>These changes represent a positive shift away from complex passwords; however, even the best-managed passwords remain susceptible to risks.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Why Passwords Are No Longer Sufficient<\/strong><\/p>\n<p>While NIST\u2019s guidelines advocate for password managers and multi-factor authentication (MFA), we believe the future lies in eliminating passwords altogether. Passwords, even when managed with care, remain vulnerable to threats like phishing, credential reuse, and data breaches.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/2021-2024%20web%20site%20images\/Asset%20images\/passwordless_keyless-1.png?width=300&amp;height=216&amp;name=passwordless_keyless-1.png\" alt=\"passwordless_keyless-1\" \/><\/p>\n<p>In fact, according to IBM, compromised credentials are the initial attack vector in 16% of breaches, while Verizon reports that nearly 38% of breaches involve credential compromise.<\/p>\n<p>At SSH, we\u2019re pushing the envelope by combining advanced biometric authentication with robust authorization controls for secure access to critical resources. This approach creates an end-to-end passwordless model for privileged access management, from verifying user identity to assigning roles and privileges during each session.<\/p>\n<p>With this approach, users never see or handle credentials, eliminating the need to manage them. This creates a multi-layered defense that is more secure, scalable, and user-friendly than traditional password-based methods.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Beyond NIST: The Path to Passwordless Security<\/strong><\/p>\n<p>NIST\u2019s guidelines lay the foundation for a more secure framework, but at SSH, we are advancing beyond traditional password management to fully passwordless solutions. Our commitment is to deliver security that not only meets but redefines regulatory standards.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>About DT Asia<\/strong><\/p>\n<p>DT Asia began in 2007 with a clear mission to build the market entry for various pioneering IT security solutions from the US, Europe and Israel.<\/p>\n<p>Today, DT Asia is a regional, value-added distributor of cybersecurity solutions providing cutting-edge technologies to key government organisations and top private sector clients including global banks and Fortune 500 companies. We have offices and partners around the Asia Pacific to better understand the markets and deliver localised solutions.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>How we help<\/strong><\/p>\n<p>If you need to know more about NIST guidelines, you\u2019re in the right place, we\u2019re here to help! DTA is SSH\u2019s distributor, especially in Singapore and Asia, our technicians have deep experience on the product and relevant technologies you can always trust, we provide this product\u2019s turnkey solutions, including consultation, deployment, and maintenance service.<\/p>\n<p>Click here and here and here to know more:\u00a0<a href=\"https:\/\/dtasiagroup.com\/vi\/ssh\/\">https:\/\/dtasiagroup.com\/ssh\/<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>The landscape of password management is evolving rapidly. Recent guidance from the National Institute of Standards and Technology (NIST) is challenging outdated norms, such as frequent password changes and complex requirements that were once seen as essential to security.<\/p>","protected":false},"author":11,"featured_media":14336,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-14335","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=14335"}],"version-history":[{"count":3,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14335\/revisions"}],"predecessor-version":[{"id":14339,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14335\/revisions\/14339"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/14336"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=14335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=14335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=14335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}