{"id":14335,"date":"2024-11-04T12:15:40","date_gmt":"2024-11-04T06:15:40","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=14335"},"modified":"2024-11-04T12:16:15","modified_gmt":"2024-11-04T06:16:15","slug":"nist-guidelines-why-its-time-to-rethink-passwords","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/nist-guidelines-why-its-time-to-rethink-passwords\/","title":{"rendered":"NIST Guidelines: Why it&#8217;s time to rethink passwords"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-14336 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2024\/11\/13297241720821794700.jpeg\" alt=\"\" width=\"500\" height=\"261\" \/><\/p>\n<p>The landscape of password management is evolving rapidly. Recent guidance from the National Institute of Standards and Technology (NIST) is challenging outdated norms, such as frequent password changes and complex requirements that were once seen as essential to security.<\/p>\n<p>While these updates mark progress, SSH Communications Security believes it\u2019s time to take an even bolder step: moving beyond passwords entirely.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Shifting Perspectives on Password Security<\/strong><\/p>\n<p>NIST\u2019s updated guidelines reflect a reimagined approach to password security. For example, they now recommend a minimum password length of 8 characters (with support up to 64 characters) and suggest eliminating periodic changes unless there\u2019s evidence of compromise. They also discourage using security questions and hints, opting for stronger verification methods, and endorse password managers to handle complex passwords more efficiently.<\/p>\n<p>Although these changes improve the security landscape, we believe there\u2019s an even better way forward\u2014one that doesn\u2019t rely on passwords at all.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Key Recommendations in NIST\u2019s Guidance<\/strong><\/p>\n<p>NIST\u2019s guidance includes the following recommendations:<\/p>\n<ul>\n<li>Minimum password length of 8 characters, with a preference for 15 characters or more.<\/li>\n<li>Allowing up to 64 characters in password length.<\/li>\n<li>Accepting a broad range of characters, including all printing ASCII characters, spaces, and even Unicode characters.<\/li>\n<li>Avoiding composition rules, like mixing character types, that add complexity without significantly boosting security.<\/li>\n<li>Removing the need for periodic password changes, unless a compromise is suspected.<\/li>\n<li>Prohibiting the use of hints accessible to unauthenticated users.<\/li>\n<li>Avoiding knowledge-based questions, such as \u201cWhat\u2019s your mother\u2019s maiden name?\u201d<\/li>\n<li>Ensuring that the full password is verified without truncation.<\/li>\n<\/ul>\n<p>These changes represent a positive shift away from complex passwords; however, even the best-managed passwords remain susceptible to risks.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Why Passwords Are No Longer Sufficient<\/strong><\/p>\n<p>While NIST\u2019s guidelines advocate for password managers and multi-factor authentication (MFA), we believe the future lies in eliminating passwords altogether. Passwords, even when managed with care, remain vulnerable to threats like phishing, credential reuse, and data breaches.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.ssh.com\/hs-fs\/hubfs\/2021-2024%20web%20site%20images\/Asset%20images\/passwordless_keyless-1.png?width=300&amp;height=216&amp;name=passwordless_keyless-1.png\" alt=\"passwordless_keyless-1\" \/><\/p>\n<p>In fact, according to IBM, compromised credentials are the initial attack vector in 16% of breaches, while Verizon reports that nearly 38% of breaches involve credential compromise.<\/p>\n<p>At SSH, we\u2019re pushing the envelope by combining advanced biometric authentication with robust authorization controls for secure access to critical resources. This approach creates an end-to-end passwordless model for privileged access management, from verifying user identity to assigning roles and privileges during each session.<\/p>\n<p>With this approach, users never see or handle credentials, eliminating the need to manage them. This creates a multi-layered defense that is more secure, scalable, and user-friendly than traditional password-based methods.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Beyond NIST: The Path to Passwordless Security<\/strong><\/p>\n<p>NIST\u2019s guidelines lay the foundation for a more secure framework, but at SSH, we are advancing beyond traditional password management to fully passwordless solutions. Our commitment is to deliver security that not only meets but redefines regulatory standards.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Ch\u00fang t\u00f4i h\u1ed7 tr\u1ee3 nh\u01b0 th\u1ebf n\u00e0o<\/strong><\/p>\n<p>If you need to know more about NIST guidelines, you\u2019re in the right place, we\u2019re here to help! DTA is SSH\u2019s distributor, especially in Singapore and Asia, our technicians have deep experience on the product and relevant technologies you can always trust, we provide this product\u2019s turnkey solutions, including consultation, deployment, and maintenance service.<\/p>\n<p>Nh\u1ea5n v\u00e0o \u0111\u00e2y \u0111\u1ec3 t\u00ecm hi\u1ec3u th\u00eam:\u00a0<a href=\"https:\/\/dtasiagroup.com\/vi\/ssh\/\">https:\/\/dtasiagroup.com\/ssh\/<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>The landscape of password management is evolving rapidly. Recent guidance from the National Institute of Standards and Technology (NIST) is challenging outdated norms, such as frequent password changes and complex requirements that were once seen as essential to security.<\/p>","protected":false},"author":11,"featured_media":14336,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-14335","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=14335"}],"version-history":[{"count":3,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14335\/revisions"}],"predecessor-version":[{"id":14339,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/14335\/revisions\/14339"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/14336"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=14335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=14335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=14335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}