<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dustin Got It Right in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Dustin-Got-It-Right/m-p/30311#M1972</link>
    <description>&lt;P&gt;Without quoting Randall Munroe's sublime password demystifying cartoon myself (I'll let &lt;A href="https://gizmodo.com/the-guy-who-invented-those-annoying-password-rules-now-1797643987" target="_blank" rel="noopener"&gt;this Gizmodo article&lt;/A&gt; do that for me!), I remember reading how a retired NIST bureaucrat admitted that he wrote bad password creation guidance -- but only after he left his role.&lt;BR /&gt;&lt;BR /&gt;Maybe at some point, someone will revise 800-63 Appendix A by appending it to say "or just use a thirty character passphrase, and at least *consider* adding MFA."&lt;/P&gt;</description>
    <pubDate>Mon, 02 Dec 2019 00:11:49 GMT</pubDate>
    <dc:creator>ericgeater</dc:creator>
    <dc:date>2019-12-02T00:11:49Z</dc:date>
    <item>
      <title>Dustin Got It Right</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Dustin-Got-It-Right/m-p/30293#M1970</link>
      <description>&lt;P&gt;Dustin's 12/1/2019 Sunday Comic got two things right in a commentary on passwords:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.comicskingdom.com/shared_comics/2e258750-c12c-4c5c-8928-e4bea6bee071" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.comicskingdom.com/shared_comics/2e258750-c12c-4c5c-8928-e4bea6bee071&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Treating all passwords as if they are protecting the same level of highly sensitive information or extreme risk is silly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.&amp;nbsp;Continuing the broadly enforced &amp;nbsp;&lt;A href="https://doi.org/10.6028/NIST.SP.800-63b" target="_blank" rel="noopener"&gt;out of date password&amp;nbsp;complexity and refresh rules&lt;/A&gt; is not only cumbersome, but stupid.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Craig&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Dec 2019 14:03:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Dustin-Got-It-Right/m-p/30293#M1970</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2019-12-01T14:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Dustin Got It Right</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Dustin-Got-It-Right/m-p/30311#M1972</link>
      <description>&lt;P&gt;Without quoting Randall Munroe's sublime password demystifying cartoon myself (I'll let &lt;A href="https://gizmodo.com/the-guy-who-invented-those-annoying-password-rules-now-1797643987" target="_blank" rel="noopener"&gt;this Gizmodo article&lt;/A&gt; do that for me!), I remember reading how a retired NIST bureaucrat admitted that he wrote bad password creation guidance -- but only after he left his role.&lt;BR /&gt;&lt;BR /&gt;Maybe at some point, someone will revise 800-63 Appendix A by appending it to say "or just use a thirty character passphrase, and at least *consider* adding MFA."&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 00:11:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Dustin-Got-It-Right/m-p/30311#M1972</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2019-12-02T00:11:49Z</dc:date>
    </item>
  </channel>
</rss>

