Главная
Study mode:
on
1
Intro
2
Disclaimer
3
A little about SP 800-63
4
The SP 800-63-3 update
5
Guiding principles
6
Standards language
7
What's in and out in 2016?
8
Maximum length
9
Space characters
10
Character set
11
Hints and prompts
12
Throttling
13
Composition
14
Dictionaries: questions
15
Dictionary investigation
16
Dictionaries: takeaways
17
Verifier storage
18
Displaying secrets
19
Memorized Secret expiration
20
Pre-registered knowledge
21
Out of Band authenticator
22
SMS as OOB authenticator
23
Biometrics
24
Join the conversation
Description:
Explore the evolving landscape of password security in this 57-minute conference talk from BSidesLV 2016. Delve into Jim Fenton's insights on improving password requirements, covering topics such as the SP 800-63-3 update, guiding principles, and standards language. Learn about crucial aspects of password management, including maximum length, character sets, composition rules, and dictionary usage. Examine the implications of verifier storage, secret display practices, and memorized secret expiration. Gain understanding of pre-registered knowledge, out-of-band authenticators, and the role of biometrics in modern authentication. Engage with the ongoing conversation surrounding password security and discover strategies for implementing more effective password policies.

Toward Better Password Requirements

BSidesLV
Add to list
0:00 / 0:00