Tagged articles

NIST

8 articles · Page 1 of 1
Frontline Investigation
Frontline Investigation
Oct 2, 2026 · Industry Insights

Why Citations Don't Make Knowledge Base Answers Trustworthy

The article explains that knowledge base assistants often provide citations that don't actually support their conclusions, creating a trust gap; it argues for verifying citations rather than just displaying them, highlighting three critical distances and suggesting systems should admit uncertainty more often.

NISTOWASPRAG
0 likes · 8 min read
Why Citations Don't Make Knowledge Base Answers Trustworthy
Frontline Investigation
Frontline Investigation
Sep 21, 2026 · Artificial Intelligence

AI Summaries Are Getting Better—But Which Exceptions Are Silently Dropped?

The article explores how AI-generated summaries tend to flatten uncertainties, conflicting judgments, unconventional actions, and evolving contexts—four types of exceptions that signal unresolved issues. It argues for preserving 'undecided positions' in summaries to maintain traceability, enable judgment relay, and prevent overconfidence in smoothed-over conclusions, citing NIST and OWASP risk frameworks.

AI summarizationAI trustworthinessNIST
0 likes · 10 min read
AI Summaries Are Getting Better—But Which Exceptions Are Silently Dropped?
dbaplus Community
dbaplus Community
Sep 12, 2026 · Information Security

Bill Burr's 2003 Password Rules Were Wrong: He Apologized in 2017

The article traces mandatory complex password rules to Bill Burr's 2003 NIST guide based on a 1980s paper, reveals how they create predictable patterns, cites xkcd's entropy comparison, and notes Burr's 2017 regret and NIST's updated guidelines, yet many sites still enforce the outdated rules.

AuthenticationBill BurrNIST
0 likes · 7 min read
Bill Burr's 2003 Password Rules Were Wrong: He Apologized in 2017
Frontline Investigation
Frontline Investigation
Sep 3, 2026 · Information Security

Permission Revoked, Data Still Visible? Uncovering the Four Dimensions of Access Residuals

This article analyzes why revoking user permissions often fails to stop data access, identifying four dimensions of visibility residuals—people, paths, data, and time—and proposes a three-layer verification framework (action, path, result) to ensure actual access termination beyond mere authorization removal.

ABACAccess ControlNIST
0 likes · 11 min read
Permission Revoked, Data Still Visible? Uncovering the Four Dimensions of Access Residuals
ITPUB
ITPUB
Aug 13, 2026 · Information Security

The NIST Official Who Enforced Special Characters in Passwords Has Apologized

The article traces the origin of the ubiquitous NIST password rule requiring uppercase letters, numbers, and special characters to an eight‑page 2003 guideline authored by Bill Burr, examines why the rule fails for human‑chosen passwords, and explains how NIST later rescinded it after the author expressed regret.

AuthenticationNISTinformation security
0 likes · 6 min read
The NIST Official Who Enforced Special Characters in Passwords Has Apologized
IT Services Circle
IT Services Circle
Jun 25, 2026 · Information Security

The NIST Official Who Mandated Special Characters in Passwords Has Apologized

The article traces the 2003 NIST password guideline that forced mixed‑case, numbers and symbols, shows how billions followed the same predictable patterns, presents real‑world leak analysis and the famous xkcd comparison, and explains why the rule was revised in 2017 yet still lingers.

NISTinformation securitypassphrase
0 likes · 6 min read
The NIST Official Who Mandated Special Characters in Passwords Has Apologized