Open Source Security

By Josh Bressers

The new NIST password guidance

🔊 Play episode (36 min)

Direct episode link

💬 Share episode

Published December 29, 2024 6:00pm

Josh and Kurt talk about new NIST password guidance. There's some really good stuff in this new document. Ideas like usability and equity show up (which is amazing). There's more strict guidance against rotating passwords and complex passwords. This new guidance gives us a lot to look forward to. Show Notes Usagi Electric NIST proposes barring some of the most nonsensical password rules NIST SP 800-63(B) STRIDE threat model PASTA threat model

Return to podcast