{"id":13884,"date":"2024-09-28T15:16:15","date_gmt":"2024-09-28T15:16:15","guid":{"rendered":"http:\/\/thisbiginfluence.com\/?p=13884"},"modified":"2024-09-28T15:16:15","modified_gmt":"2024-09-28T15:16:15","slug":"the-us-could-finally-ban-inane-forced-password-changes","status":"publish","type":"post","link":"https:\/\/thisbiginfluence.com\/?p=13884","title":{"rendered":"The US Could Finally Ban Inane Forced Password Changes"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Researchers discovered a vulnerability in a <a href=\"https:\/\/www.wired.com\/story\/kia-web-vulnerability-vehicle-hack-track\/\">Kia web portal that allowed them to track millions of cars, unlock doors, honk horns, and even start engines<\/a> in seconds, simply by studying the automobile&#8217;s license plate. The findings are the most recent in a string of net bugs which have impacted dozen of carmakers. In the meantime, a handful of <a href=\"https:\/\/www.wired.com\/story\/tesla-cybertruck-russia-ukraine-war\/\">Tesla Cybertrucks have been outfitted for war<\/a> and are actually being-battle examined by Chechen forces preventing in Ukraine as a part of Russia\u2019s ongoing invasion.<\/p>\n<p class=\"paywall\">As Israel escalates its assaults on Lebanon, <a href=\"https:\/\/www.wired.com\/story\/amid-air-strikes-and-rockets-an-sms-from-the-enemy\/\">civilians on both sides of the conflict have been receiving ominous text messages<\/a>\u2014and authorities in every nation are accusing the opposite of psychological warfare. The US authorities has more and more condemned Russia-backed media retailers like RT for working intently with Russian intelligence\u2014and plenty of digital platforms have eliminated or banned their content material. However <a href=\"https:\/\/www.wired.com\/story\/russia-backed-media-outlets-are-under-fire-in-the-us-but-still-trusted-worldwide\/\">they\u2019re still influential and trusted alternative sources of information in many parts of the world<\/a>.<\/p>\n<p class=\"paywall\">And there is extra. Every week, we spherical up the privateness and safety information we didn\u2019t cowl in depth ourselves. Click on the headlines to learn the complete tales. And keep secure on the market.<\/p>\n<p class=\"paywall\">A brand new draft of the US Nationwide Institute of Requirements and Expertise&#8217;s \u201cDigital Id Tips\u201d lastly takes steps to get rid of reviled password administration practices which have been proven to do extra hurt than good. The suggestions, which might be obligatory for US federal authorities entities and function pointers for everybody else, ban the follow of requiring customers to periodically change their account passwords, usually each 90 days.<\/p>\n<p class=\"paywall\">The coverage of recurrently altering passwords advanced out of a need to make sure that individuals weren&#8217;t selecting simply guessable or reused passwords; however in follow, it causes individuals to decide on easy or formulaic passwords so they are going to be simpler to maintain observe of. The brand new suggestions additionally ban \u201ccomposition guidelines,\u201d like requiring a sure quantity or mixture of capital letters, numbers, and punctuation marks in every password. NIST writes within the draft that the purpose of the Digital Id Tips is to offer \u201cfoundational threat administration processes and necessities that allow the implementation of safe, personal, equitable, and accessible id methods.\u201d<\/p>\n<p class=\"paywall\">The US Division of Justice unsealed expenses on Friday towards three Iranian males who allegedly compromised Donald Trump\u2019s presidential marketing campaign and leaked stolen knowledge to media retailers. Microsoft and Google warned final month that an Iranian state-sponsored hacking group generally known as APT42 had focused each the Joe Biden and Donald Trump presidential campaigns, and efficiently breached the Trump marketing campaign. The DOJ claims the hackers compromised a dozen individuals as a part of its operation, together with a journalist, a human rights advocate, and a number of other former US officers. Extra broadly, the US authorities has mentioned in latest weeks that Iran is making an attempt to intrude within the 2024 election.<\/p>\n<p class=\"paywall\">\u201cThe defendants\u2019 personal phrases made clear that they had been making an attempt to undermine former President Trump\u2019s marketing campaign prematurely of the 2024 U.S. presidential election,\u201d Legal professional Normal Merrick Garland <a href=\"https:\/\/www.justice.gov\/opa\/speech\/attorney-general-merrick-b-garland-delivers-remarks-announcing-results-operation-north\">said<\/a> at a press convention on Friday. &#8220;We all know that Iran is constant with its brazen efforts to stoke discord, erode confidence within the US electoral course of, and advance its malign actions.\u201d<\/p>\n<p class=\"paywall\">The Irish Knowledge Safety Fee fined Meta \u20ac91 million, or roughly $101 million, on Friday for a <a href=\"https:\/\/www.wired.com\/story\/facebook-passwords-plaintext-change-yours\/\">password storage lapse in 2019<\/a> that violated the European Union&#8217;s Normal Knowledge Safety Regulation. Following a <a data-offer-url=\"https:\/\/krebsonsecurity.com\/2019\/03\/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/krebsonsecurity.com\/2019\/03\/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years\/&quot;}\" href=\"https:\/\/krebsonsecurity.com\/2019\/03\/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years\/\" rel=\"nofollow noopener\" target=\"_blank\">report by Krebs on Security<\/a>, the corporate acknowledged in March 2019 {that a} bug in its password administration methods had precipitated lots of of hundreds of thousands of Fb, Fb Lite, and Instagram passwords to be saved with out safety in plaintext in an inside platform. Eire&#8217;s privateness watchdog launched its investigation into the incident in April 2019.<\/p>\n<p class=\"paywall\">\u201cIt&#8217;s broadly accepted that consumer passwords shouldn&#8217;t be saved in plaintext, contemplating the dangers of abuse that come up from individuals accessing such knowledge,&#8221; Irish DPC deputy commissioner Graham Doyle mentioned in an announcement. \u201cIt should be borne in thoughts that the passwords, the topic of consideration on this case, are notably delicate, as they might allow entry to customers\u2019 social media accounts.\u201d<\/p>\n<p class=\"paywall\">The digital anonymity nonprofit the Tor Challenge is merging with privacy- and anonymity-focused Linux-based working system Tails. Pavel Zoneff, the Tor Challenge\u2019s communications director, wrote in a weblog submit on Thursday that the transfer will facilitate collaboration and cut back prices, whereas increasing each teams&#8217; attain. \u201cTor and Tails present important instruments to assist individuals around the globe keep secure on-line,\u201d he wrote. \u201cBy becoming a member of forces, these two privateness advocates will pool their sources to concentrate on what issues most: making certain that activists, journalists, different at-risk and on a regular basis customers could have entry to improved digital safety instruments.\u201d<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.wired.com\/story\/nist-password-guidance-improvements\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers discovered a vulnerability in a Kia web portal that allowed them to track millions of cars, unlock doors, honk horns, and even start engines in seconds, simply by studying the automobile&#8217;s license plate. The findings are the most recent in a string of net bugs which have impacted dozen of carmakers. In the meantime, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":13886,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[751,745,2723,10746,8677],"class_list":["post-13884","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech","tag-ban","tag-finally","tag-forced","tag-inane","tag-password"],"_links":{"self":[{"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/posts\/13884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=13884"}],"version-history":[{"count":0,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/posts\/13884\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=\/wp\/v2\/media\/13886"}],"wp:attachment":[{"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=13884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=13884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thisbiginfluence.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=13884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}