-
-
Notifications
You must be signed in to change notification settings - Fork 57
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Align Password (and more generaly authentication) section with NIST SP 800-63-4B #27
Comments
Can you be more specific? |
As provided through the link:
Plus:
The diff is:
Also Password Reset section has no strong guidance against the "Usage of Knowledge Based Authentication". Hope this is clearer. |
Thanks! Honestly we could just get rid of the zxcvbn recommendation. And I was planning to add the notify user recommendation. The brute force section talks about MFA but do you think we should put more emphasis on it? |
MFA is good fallback (augment friction if assurance in transaction decrease). Now the core function should be around analytics of Authentication events. |
there are some discrepancies on the guidance for the forms of authentication with https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63B-4.2pd.pdf
The text was updated successfully, but these errors were encountered: