57
submitted 1 day ago* (last edited 18 hours ago) by NullNet@lemmy.blahaj.zone to c/cybersecurity@infosec.pub

Small rant incomming. I just went to look at applying to Walmart, and when going to make an account their password requirements were 8-11 characters. What kinda nonsense is that? Some terribly made backend I'd assume. It's bad enough I gotta make a million accounts when applying to jobs but then you got my PII sitting behind such terrible password requirements it makes me wonder where else they are cutting corners on security.

you are viewing a single comment's thread
view the rest of the comments
[-] cynar@lemmy.world 3 points 18 hours ago

There are use cases where long passwords could be problematic. 64 would be long enough for most purposes, but short enough not to cause issues for things like microcontrollers.

It should be paired with a strongly recommended larger value, however.

[-] subtext@lemmy.world 6 points 15 hours ago

The new NIST recommendations give a recommendation of at least a 64 character maximum.

Verifiers and CSPs SHOULD permit a maximum password length of at least 64 characters.

https://pages.nist.gov/800-63-4/sp800-63b.html#passwordver

this post was submitted on 28 Nov 2024
57 points (96.7% liked)

cybersecurity

3306 readers
172 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 1 year ago
MODERATORS