{"id":1187,"date":"2013-03-19T11:24:25","date_gmt":"2013-03-19T17:24:25","guid":{"rendered":"http:\/\/wp.natsci.colostate.edu\/cnsit\/?p=1187"},"modified":"2022-04-25T14:24:43","modified_gmt":"2022-04-25T20:24:43","slug":"acns-and-csu-netid-password-policy-update","status":"publish","type":"post","link":"https:\/\/cnsit.colostate.edu\/kb\/acns-and-csu-netid-password-policy-update\/","title":{"rendered":"ACNS and CSU NetID Password Policy Update"},"content":{"rendered":"<p>As you have probably heard, ACNS is updating the NetID password Policy, starting April 1st.\u00a0 This change will not affect everyone at once, but beginning in April, all new password reset messages you conduct will require the following rules to be applied:<\/p>\n<ol>\n<li>Passwords must be between 15 and 30 characters long.<\/li>\n<li>Passwords must include at least one letter.<\/li>\n<li>There\u2019s no requirement to use upper-case or special characters (though they can be chosen, other than those in #4).<\/li>\n<li>The same list of special characters NOT to choose based on some back-end Oracle applications is still with us; now it\u2019s enforced across the board, for consistency and ease of support. Note that this includes a prohibition against blank spaces. (Banned Characters: @ $ &amp; &#8221; ( ) &#8216; ; = # * blank_space &lt; &gt; , )<\/li>\n<li>Certain password choices are not allowed, and will be prevented by the password change tool:\n<ul>\n<li>The user\u2019s NetID, real first name and real last name cannot be used as part of the password.<\/li>\n<li>Single 15+ character words are not allowed (this is called a \u201cdictionary check\u201d).<\/li>\n<li>Password history will be retained and checked: the user must choose a different password at each change.<\/li>\n<li>Some weak choices and easily guessed phrases are also being blocked (including sequential strings like \u2018abcdefgh\u2019, movie\/book titles, CSU fight song lyrics, and passwords used as examples on the web site and in presentations that have been given as part of this policy transition).<\/li>\n<\/ul>\n<\/li>\n<li>With this new list of requirements, the refresh rate moves from 6 months to 1 year. So any password created after April 1st will be good for a year from the date of the change.<\/li>\n<\/ol>\n<p>Here are some of the concepts that drove ACNS in the decision-making for the new policy:<\/p>\n<ol>\n<li>Our current password scheme is simply too weak, given the advances in attacks.<\/li>\n<li>In choosing a stronger password, we want to avoid unnecessary complication and ease usage wherever possible.<\/li>\n<li>Expanded use of mobile devices has made traditional \u201cstrong\u201d passwords, which rely on excessive complexity and obfuscation, increasingly difficult to use (particularly on phones that require multiple screens to access all the special characters).<\/li>\n<li>Difficulty of guessing, difficulty of remembering, and difficulty of typing a password are separate concepts.\n<ul>\n<li>Our current scheme asks users to select passwords that can be difficult to remember and type, but are easy for computers to guess.<\/li>\n<li>Our goal is to create passwords that are easy for humans to remember and type, but hard for computers to guess.<\/li>\n<\/ul>\n<\/li>\n<li>So here\u2019s how longer, simpler passwords address those three concepts (guessing, remembering, and typing):\n<ul>\n<li>Longer strings of lower-case letters, even when arranged into a sequence of real words, can provide better defense against guessing than short, complex character strings. Expressed differently: length is much more important than complexity.<\/li>\n<li>A string of common words can be more easily memorized than a string of nonsense characters or special-character substitutions. Each word can be remembered as a \u201cchunk\u201d, requiring only a few word-sized chunks rather than a much longer series of individual special characters or substitutions.<\/li>\n<li>A sequence of real words in all lower-case letters is easier to type than special characters that require Shift or Alt on a normal keyboard or additional entry screens on mobile devices.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>And, finally, here is some much needed comic relief: <a href=\"http:\/\/xkcd.com\/936\">http:\/\/xkcd.com\/936<\/a><\/p>\n<p style=\"text-align: center;\"><a href=\"http:\/\/xkcd.com\/936\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter  wp-image-1202\" title=\"Click to view the full sized image from the source: http:\/\/xkcd.com\/936\" src=\"http:\/\/imgs.xkcd.com\/comics\/password_strength.png\" alt=\"password_strength\" width=\"592\" height=\"481\" \/><\/a><\/p>\n<p style=\"text-align: center;\">\n","protected":false},"excerpt":{"rendered":"<p>As you have probably heard, ACNS is updating the NetID password Policy, starting April 1st.\u00a0 This change will not affect everyone at once, but beginning in April, all new password reset messages you conduct will require the following rules to be applied: Passwords must be between 15 and 30 characters long. Passwords must include at [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1194,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,10],"tags":[],"class_list":["post-1187","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general-cnsit","category-security"],"_links":{"self":[{"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/posts\/1187","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/comments?post=1187"}],"version-history":[{"count":1,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/posts\/1187\/revisions"}],"predecessor-version":[{"id":4415,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/posts\/1187\/revisions\/4415"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/media\/1194"}],"wp:attachment":[{"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/media?parent=1187"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/categories?post=1187"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cnsit.colostate.edu\/kb\/wp-json\/wp\/v2\/tags?post=1187"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}