Are regulations keeping you from using good passwords?

May 30, 2018

I rarely go to a conference where I don’t hear someone doling out “good” password policy advice. You know, the password policy includes:

Eight to 12 characters long as a minimum; extremely long passphrases are better

Must be complex and include at least three different character sets (e.g., uppercase characters, lowercase characters, numbers, or symbols)

Change every 90 days or fewer

Enable account lockouts for bad passwords, five bad attempts or fewer

