DiscoverSysAdmin Weekly030 - New NIST Password Guidelines Explained
030 - New NIST Password Guidelines Explained

030 - New NIST Password Guidelines Explained

Update: 2025-11-14
Share

Description

Ready to leave password chaos behind? In this episode of SysAdmin Weekly, Andy and Eric break down the latest National Institute of Standards and Technology (NIST) password and identity-guideline updates and what they mean for you as a SysAdmin.

We cover:

- What changed and why (goodbye “special characters just because”)

- How to align your org with SP 800-63’s new structure and expectations

- Real-world tactics: from passkeys and token theft to legacy systems refusing to die

Also in this episode: bonus snark, smart home horror stories, PKI headaches, and identity as the new firewall

Whether you’re revamping your password policy or finally ready to ditch the “rotate every 90 days” mindset, this one’s for you.


Episode Resources

- SysAdmin Weekly website

- SysAdmin Weekly companion newsletter

- AndyOnTech

- Project Runspace

- NIST Digital Identity Guidelines (SP 800-63 suite)

- NIST SP 800-63B “Authentication & Authenticator Management”

- Evilginx2 (GitHub repo for the MITM/phishing framework)

Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

030 - New NIST Password Guidelines Explained

030 - New NIST Password Guidelines Explained

Andy Syrewicze and Eric Siron