{"id":4368,"date":"2017-07-05T11:58:47","date_gmt":"2017-07-05T15:58:47","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=4368"},"modified":"2017-07-14T13:18:03","modified_gmt":"2017-07-14T17:18:03","slug":"nist-password-pasting","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/nist-password-pasting\/","title":{"rendered":"NIST Officially Recommends Password Pasting"},"content":{"rendered":"<h2>Official Password Guidelines Validate What the Security Community Has Said For Ages<\/h2>\n<p>The U.S. National Institute of Standards and Technology, or NIST, is heavily involved in setting security standards and is a regular contributor to the field of cryptography. For instance, the NIST have published curves for use in ECC, and hosted the competition that led to the development of SHA-3.<\/p>\n<p>Last month they published <a href=\"https:\/\/pages.nist.gov\/800-63-3\/\" rel=\"nofollow\">SP 800-63: Digital Identity Guidelines<\/a>. While the name may put you to sleep, what was written inside electrified the security community. <span id=\"newline\"><\/span><\/p>\n<p>The four-volume series of documents outlines how systems should handle account security, including passwords, two-factor authentication, and related policies. NIST publishes similar documents on all types of security topics with the goal of assisting engineers who need to implement these systems.<\/p>\n<p>One of the topics it commented on was \u2018password pasting,\u2019 the practice of allowing users to paste their passwords into login forms. The NIST\u2019s verdict? It\u2019s Good.<\/p>\n<p>Even though the security community<a href=\"https:\/\/www.troyhunt.com\/the-cobra-effect-that-is-disabling\/\" rel=\"nofollow\"> have known for a long time<\/a> that disabling pasting is a bad idea, it is still a commonly held belief that it somehow improves security:<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Hello, a long password is a great way to protect your information! For security purposes we do not allow pasting of passwords.<\/p>\n<p>\u2014 TurboTax Support (@TeamTurboTax) <a href=\"https:\/\/twitter.com\/TeamTurboTax\/status\/848674657125507073\" rel=\"nofollow\">April 2, 2017<\/a><\/p><\/blockquote>\n<p><a href=\"\/\/platform.twitter.com\/widgets.js\">\/\/platform.twitter.com\/widgets.js<\/a><\/p>\n<p>However there is just no evidence to back that up. One misconception is that it somehow stops brute-force attacks, however there are a number of better methods to defend against that (rate limiting), and attackers won\u2019t be using a standard browser to break into your account anyways.<\/p>\n<p>As the NIST\u2019s <a href=\"http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-63b.pdf\" rel=\"nofollow\">new guidelines say<\/a>, users should be able \u201cto use \u2018paste\u2019 functionality when entering a [password]. This facilitates the use of password managers, which are widely used and in many cases increase the likelihood that users will choose stronger memorized secrets.\u201d<\/p>\n<p>I don\u2019t know about you, but typing a secure password such as \u201c?tgZ8t3Xwr\u201d is almost as difficult as remembering it would be. Given the importance of using strong and <em>unique <\/em>passwords for every service, allowing pasting is essentially the only way you can ensure users can do that.<\/p>\n<p>Earlier this year the National Cyber Security Centre (NCSC), the UK\u2019s official authority on cyber security, <a href=\"https:\/\/www.ncsc.gov.uk\/blog-post\/let-them-paste-passwords\" rel=\"nofollow\">also endorsed the use of paste<\/a>.<\/p>\n<p>The NIST\u2019s new guidelines included a number of other best-practice recommendations for passwords including support for 64-character (or longer) passwords, and that periodic (e.g. \u201cevery X months\u201d) password changes should not be used. They also say that systems should accept Unicode, all printable ASCII characters, and spaces,<\/p>\n<p>Those working in the field of security have known these are best practices for quite some time. However, NIST included another guideline which is surprisingly progressive:<\/p>\n<p>\u201c[Systems] SHALL compare the prospective secrets against a list that contains values known to be commonly-used, expected, or compromised.\u201d<\/p>\n<p>In the world of internet standards, <em>SHALL <\/em>written in uppercase letters has a special meaning. The <a href=\"https:\/\/www.ietf.org\/rfc\/rfc2119.txt\" rel=\"nofollow\">IETF has formally defined different terms to be used in standards<\/a>, and in this case shall means \u201crequired.\u201d<\/p>\n<p>One of the suggested sources for these \u201cknown compromised\u201d passwords is from lists of \u201cpasswords obtained from previous breach corpuses.\u201d This is a rather cutting-edge suggestion which would have the passwords of registered users compared to known databases of compromised account credentials.<\/p>\n<p>This would be similar to the functionality offered by <a href=\"https:\/\/haveibeenpwned.com\/\" rel=\"nofollow\">Have I Been Pwned?<\/a>, a free service that lets you know if any of your accounts were compromised as part of known breaches.<\/p>\n<p>Microsoft <a href=\"https:\/\/www.theregister.co.uk\/2016\/05\/25\/microsoft_password_policy\/\" rel=\"nofollow\">already uses this practice<\/a> but it&#8217;s quite uncommon and <a href=\"https:\/\/twitter.com\/kennwhite\/status\/874744666150850562\" rel=\"nofollow\">perceived as creepy<\/a> by some. So while the general public may not yet feel at ease with a website knowing their password was compromised elsewhere, we can all agree on this: Password pasting is Good.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Official Password Guidelines Validate What the Security Community Has Said For Ages The U.S. National Institute of Standards and Technology, or NIST, is heavily involved in setting security standards and&#8230;<\/p>\n","protected":false},"author":2,"featured_media":4369,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[3381,2726],"class_list":["post-4368","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-nist","tag-passwords","post-with-tags"],"views":13290,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/07\/iStock-615605212.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=4368"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/4368\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/4369"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=4368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=4368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=4368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}