I came here for maybe some additional context on why NIST used to have the minimum failures defined but now they don't. I found it eventually in Nist 800-63b and it's kinda completely different than the previous version of 800-63b. "No more than 100 failed attempts" and then separately, they have a usability section with "Minimum of 10 failed attempts allowed" as a usability concern. :/ I had read some summaries of the earlier versions and they seem to have just said Minumum was 10 and maximum was 100. I'm trying to be a change maker and this stuff is SPAGETTI!
Great summary! Thanks sir
I came here for maybe some additional context on why NIST used to have the minimum failures defined but now they don't. I found it eventually in Nist 800-63b and it's kinda completely different than the previous version of 800-63b. "No more than 100 failed attempts" and then separately, they have a usability section with "Minimum of 10 failed attempts allowed" as a usability concern. :/ I had read some summaries of the earlier versions and they seem to have just said Minumum was 10 and maximum was 100. I'm trying to be a change maker and this stuff is SPAGETTI!