TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

NIST proposes barring some of the most nonsensical password rules

44 点作者 ashton3148 个月前

2 条评论

Glant8 个月前
&gt; Verifiers SHALL verify the entire submitted password (i.e., not truncate it).<p>That&#x27;d be a nice world to live in. I love making an account with a service just to not be able to log in because the password that the sign up form allowed is too long for the log in form.
cge8 个月前
This article appears mistaken about which parts of the guidelines are new.<p>The recommendation against periodic password change requirements, for example, has been part of NIST guidelines for years, in previous versions of this document. This has not kept a large number of US federal and state government agencies from requiring periodic password changes, sometimes even stating that it is a regulatory requirement. It&#x27;s not clear that the NIST guidelines have any effect whatsoever on the very government NIST is part of.
评论 #41666170 未加载