Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

memorized secrets - periodic changes #2009

Open
danielpoulsen opened this issue Dec 26, 2024 · 0 comments
Open

memorized secrets - periodic changes #2009

danielpoulsen opened this issue Dec 26, 2024 · 0 comments

Comments

@danielpoulsen
Copy link

Can anyone provide references to studies with data that support the new password recommendations in sp800-63b ?

Specifically:
Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.

I've seen references to studies in many articles but I'm unable to find them. This data would help to move our organization in this direction.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant