Here is the text of the NIST sp800-63b Digital Identity Guidelines.

  • cybersandwich@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    19 hours ago

    I think if you do allow 8 character passwords the only stipulation is that you check it against known compromised password lists. Again, pretty reasonable.

    • Lvxferre@mander.xyz
      link
      fedilink
      English
      arrow-up
      0
      ·
      19 hours ago

      That stipulation goes rather close to #5, even not being a composition rule.

      I think that a better approach is to follow the recommended min length (15 chars), unless there are good reasons to lower it and you’re reasonably sure that your delay between failed password attempts works flawlessly.