3.1 Password Hygiene and Authentication
-
The “Passphrase” Standard: NIST (National Institute of Standards and Technology) now recommends length over complexity. A 15-character passphrase like
Purple-Coffee-Train-Jumpis mathematically harder to crack thanTr0ub4dor&3and easier to remember. -
Credential Stuffing: Users often reuse passwords. If
LinkedInis breached, hackers try that same email/password combo onSalesforce,Office 365, andBanking. Rule: Never reuse corporate credentials. -
MFA (Multi-Factor Authentication): This is non-negotiable. It blocks 99.9% of automated attacks. However, beware of MFA Fatigue, where attackers spam your phone with push notifications hoping you click “Approve” just to make it stop.