多年来广泛推行的密码复杂性要求——包括大小写字母、数字和特殊字符的组合——原本旨在提高账户安全,但越来越多的证据表明这些规则可能产生相反效果。1这些指导方针由美国国家标准与技术研究院(NIST)在2004年发布,但随后的研究和实践经验暴露了其缺陷。1
NIST本身也改正了这一立场。该机构密码指导的原始制定者威廉·伯尔在2017年对《华尔街日报》表示他对这一指导"感到遗憾",指出"规则太复杂"。1同年,NIST更新了其指导方针,反对强制字符组成规则和例行密码更换。1
研究进一步质证了复杂性规则的有效性。2021年詹姆斯库克大学的研究发现,增加密码复杂性规则的数量并不一定能产生更强的密码。1专家洛瑞·克拉诺的研究建议采取不同的策略,推荐使用密码强度计和密码管理工具,而非依赖复杂字符要求。1现行的安全建议应当包括检查密码是否出现在已泄露密码列表中。1
The strict password requirements that have dominated cybersecurity guidance for nearly two decades may actually be making users less secure. The U.S. National Institute of Standards and Technology (NIST) introduced recommendations in 2004 requiring passwords to contain uppercase and lowercase letters, numbers, and special characters 1. However, NIST itself reversed course in 2017, with William Burr, who had helped develop the original guidance, expressing regret to the Wall Street Journal, saying the rules were "too complicated" 1. The updated 2017 NIST guidelines formally discouraged mandatory character composition requirements and routine password changes 1.
Research has increasingly challenged the effectiveness of these complexity-focused approaches. A 2021 study by James Cook University found that increasing the number of password complexity rules does not necessarily produce stronger passwords 1. Security researcher Lorrie Cranor's work suggests that more practical strategies—such as using password strength meters and password management tools—are more effective than enforcing complex character combinations 1. Additionally, current security best practices recommend checking whether passwords appear in databases of previously breached credentials rather than relying on character composition rules 1.
评论
还没有评论,欢迎留下第一条。