Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update advice on strong password rules #4

Open
jag1g13 opened this issue Jun 1, 2020 · 3 comments
Open

Update advice on strong password rules #4

jag1g13 opened this issue Jun 1, 2020 · 3 comments

Comments

@jag1g13
Copy link

jag1g13 commented Jun 1, 2020

Copied from Slack message:

A comment on the advice provided on passwords though (the callout sourced from https://www.webopedia.com/TERM/S/strong_password.html):

Many security conscious organisations are now recommending against what was traditionally considered the good password style (the one used by that source) and are moving towards the XKCD-style passphrase, three or four random words, due to being easier to remember and harder to guess. NCSC in particular have been recommending it for a few years https://www.ncsc.gov.uk/blog-post/three-random-words-or-thinkrandom-0.

Alternatively, machine generated passwords (https://www.ncsc.gov.uk/collection/passwords/updating-your-approach#tip5-password-collection), but these rely on the users using a password manager and being comfortable with using it from the terminal (or copying the password across every time the need it) if used for SSH.

It's possible that some of the systems being used enforce traditional password rules and don't accept XKCD-style passwords, but this in general is a fault with the password policy which they should be encouraged to change.

There may obviously be constraints which mean the traditional password design is preferred in certain cases, but in general, the current advice should be to use passphrases made from random words e.g. https://preshing.com/20110811/xkcd-password-generator/

@james-grant1
Copy link
Contributor

james-grant1 commented Jun 2, 2020

Incorporated text and links almost as wrote, in new passwords episode to follow in PR for topic-#1

james-grant1 pushed a commit to james-grant1/security that referenced this issue Jun 2, 2020
@james-grant1
Copy link
Contributor

This has now been merged into master as part of the episode refactor if you could review.

@jag1g13
Copy link
Author

jag1g13 commented Jun 3, 2020

I noticed two typos,

  • "Many meail providers" in the first paragraph
  • "passwords it typically" in the callout "Strong passwords"

But otherwise looks good to me - happy to call this closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants