Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

NIST standard suggests checking a list of leaked passwords, and setting a length requirement:

> Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. If the CSP or verifier disallows a chosen memorized secret based on its appearance on a blacklist of compromised values, the subscriber SHALL be required to choose a different memorized secret. No other complexity requirements for memorized secrets SHOULD be imposed. A rationale for this is presented in Appendix A Strength of Memorized Secrets.

https://pages.nist.gov/800-63-3/sp800-63b.html#sec4



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: