Password

24th December 2019 | Cybrary Password

Password authenticity graphic

 

Image Source

A password is a string of characters (letters, numbers, and other symbols) used to authenticate an identity or to verify access authorization.

Early password advice from NIST in 2003 was to use 9-character, complex passwords (UPPERCASE, lowercase, special characters !@#$%, and numbers) and to be changed every 90 days. In 2017, NIST amended its advice because the consequences of their early advice was less secure than their new advice.

2017 NIST password Advice was to migrate companies to 14+ character passphrases that did not require complexity nor expire.

Related Terms: Password Manager, Passphrases

Source: FIPS 140-2

To learn more about passwords, passphrases, and password managers, watch this short video:

CyberHoot does have some other resources available for your use. Below are links to all of our resources, feel free to check them out whenever you like: 

Note: If you’d like to subscribe to our newsletter, visit any link above (besides infographics) and enter your email address on the right-hand side of the page, and click ‘Send Me Newsletters’. Sign up for the monthly newsletter to help CyberHoot with their mission of making the world ‘More Aware and More Secure!’

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

Microsoft Integrates Passkeys into Windows: is this the start of a Passwordless Future?

Microsoft Integrates Passkeys into Windows: is this the start of a Passwordless Future?

Let’s be honest, who hasn’t reset a password at least once this month? For decades, passwords have been our...

Read more
When You Become the Hacker: How Modern Attacks Trick You Into Hacking Yourself

When You Become the Hacker: How Modern Attacks Trick You Into Hacking Yourself

In a shift away from the usual “hack-meets-victim” narrative, a new kind of cyber-assault is emerging. One...

Read more
Domain Takedowns: How to Remove Fraudulent and Typo-squatted Domains and Websites

Domain Takedowns: How to Remove Fraudulent and Typo-squatted Domains and Websites

In cybersecurity, not all attacks happen through fancy malware or zero-day exploits. Some of the most effective...

Read more