NIST password guidlines

NIST Special Publication 800-63B by NIST (nvlpubs.nist.gov)

Users should be encouraged to make their passwords as lengthy as they want, within reason. Since the size of a hashed password is independent of its length, there is no reason not to permit the use of lengthy passwords (or pass phrases) if the user wishes. Extremely long passwords (perhaps megabytes in length) could conceivably require excessive processing time to hash, so it is reasonable to have some limit.

The new NIST guidance on passwords recommend that:

  • passwords never expire
  • no required character complexity or variety rules be implemented
  • the maximum length for passwords be set to 64 characters
  • the minimum length for passwords be set to 8 characters
  • passwords are checked against known bad passwords, banned lists, etc.
  • no hints or knowledge-based questions be provided to someone trying to log in (like “Who was your best friend in high school?”)
  • passwords only are changed when forgotten

I would add two-factor authentication to that. Where possible, my online account passwords are sixteen characters or longer. I change them after notification of a data breach or in some cases, once a year. Where feasible, I have enabled two-factor or two-step authentication for my accounts. Even on my iMac at home, I have a 24 character password. I use a different password for each online account. I use a password vault application such as 1Password or LastPass to track my passwords. I protect the password vault with a sixteen character password that I don't use anywhere else.

Wha MacBooooooook keyboooard proooblem? All he keys ooon my daugher's 2018 MacBooooook Air wooork!

Apple apologizes for continuing MacBook keyboard problems | Cult of Mac

The MacBook keyboard problems that plagued older models still crop up in the 2018 MacBook Pro and MacBook Air. Apple has remedies, though.

Wha MacBooooooook keyboooard proooblem? All he keys ooon my daugher's 2018 MacBooooook Air wooork!

Apple apologizes for continuing MacBook keyboard problems | Cult of Mac

The MacBook keyboard problems that plagued older models still crop up in the 2018 MacBook Pro and MacBook Air. Apple has remedies, though.

She's fine so long as she does not use "o" and "t".

New York Suburb Declares Measles Emergency, Barring Unvaccinated Children From Public

New York Suburb Declares Measles Emergency, Barring Unvaccinated Children From Public (nytimes.com)

An executive order pulled close to 6,000 unvaccinated children out of schools. Nearly 17,000 doses of the measles-mumps-rubella (M.M.R.) vaccine were given in 26 weeks. There was a public health campaign in which community officials, doctors and rabbis testified to the importance of immunizations.

Anti-vaccination adherents are fucking morons. I want the government to immunize every person forcefully. You can't yell "fire" in a public space. You shouldn't be able to enter any public area without being vaccinated. If visitors to the USA are required to be vaccinated, then I see no reason why US citizens are excluded from the requirement. Require proof of vaccination for the issuance of a drivers license and passport.

Lawrence O. Gostin, a professor of global health law at Georgetown University, said he found Rockland County’s emergency order deeply problematic.

He said he is a longtime proponent of making vaccines compulsory for children to attend schools, but questioned whether the order is constitutional.

“This is virtually imprisonment of a child, and certainly significantly restricting the child’s liberty,” Mr. Gostin said.

And if it was an outbreak of Ebola what would this fucking moron say?