{"id":40438,"date":"2017-08-12T09:37:51","date_gmt":"2017-08-12T09:37:51","guid":{"rendered":"https:\/\/www.biphoo.com\/bipnews\/?p=40438"},"modified":"2017-08-12T09:37:51","modified_gmt":"2017-08-12T09:37:51","slug":"forget-everything-know-passwords-says-man-made-password-rules","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/forget-everything-know-passwords-says-man-made-password-rules.html","title":{"rendered":"Forget Everything You Know About Passwords, Says Man Who Made Password Rules"},"content":{"rendered":"<h2 style=\"text-align: justify\"><span style=\"font-size: 18pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Forget Everything You Know About Passwords, Says Man Who Made Password Rules<\/span><\/strong><\/span><\/h2>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Forget Everything You Know About Passwords, Says Man Who Made Password Rules:- For 20 years, the standard advice for creating a &#8220;strong&#8221; password that is hard to crack has been to use a mix of letters, numbers and symbols.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">It&#8217;s so ingrained that when you go to create a new email account you&#8217;ll frequently get praising or finger-wagging feedback from the computer on how well your secret code adheres to these guidelines.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">And you&#8217;re supposed to change it every 90 days.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Now, the man who laid down these widely followed rules says he got it all wrong.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cMuch of what I did I now regret,&#8221; Bill Burr, a 72-year-old retired former manager at the National Institute of Standards and Technology told the Wall Street Journal.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">In 2003, the then-mid-level NIST manager was tasked with the job of setting rules for effective passwords. Without much to go on he sourced a whitepaper written in the 1980s. The rules his agency published ended up becoming the go-to guides for major institutions and large companies.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The result is that people create odd-looking passwords and then have to write them down, which is of course less secure than something you can memorize. Users also lean on common substitutions, like &#8220;zeroes&#8221; for the letter O, which a smart hacker could program their password cracker to look for. Or they pick one &#8220;base&#8221; password that they can memorize and only change a single number. That&#8217;s also not as safe.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">\u201cIt just drives people bananas and they don\u2019t pick good passwords no matter what you do,\u201d Burr said.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">The new password guidelines are both easier to remember, and harder to guess. The NIST&#8217;s revised tips say users should pick a string of simple English words \u2014 and only be forced to change them if there&#8217;s been evidence of a security break-in.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">Not only did the old password format frustrate users, it wasn&#8217;t even the best way to keep hackers at bay.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt;font-family: Arial, Helvetica, sans-serif;color: #000000\">For instance, &#8220;Tr0ub4dor&amp;3&#8221; could take just three days to crack, according to one viral comic whose assertions have been verified by security researchers, while &#8220;CorrectHorseBatteryStaple&#8221; could take 550 years.<\/span><\/p>\n<p><span style=\"font-size: 8pt;font-family: Arial, Helvetica, sans-serif\">Source:-\u00a0http:\/\/www.nbcnews.com\/tech\/security\/forget-everything-you-know-about-passwords-says-man-who-made-n790711<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/forget-everything-know-passwords-says-man-made-password-rules.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>Forget Everything You Know About Passwords, Says Man Who Made Password Rules Forget Everything You Know About Passwords, Says Man Who Made Password Rules:- For 20 years, the standard advice for creating a &#8220;strong&#8221; password that is hard to crack has been to use a mix of letters, numbers and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":40441,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[44386],"class_list":["post-40438","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-forget-everything-you-know-about-passwords"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/40438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=40438"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/40438\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/40441"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=40438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=40438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=40438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}