Dr. Andy Farnell's Article on Why Passwords Still Rock
Have a look at "Seven for a secret never to be told; here's an excerpt:
To make things worse, there's loads of misinformation out there; cybersecurity folklore, marketing spew, lobbying efforts - and these feed-back into government too, including organisations like NIST, so perpetuating the cycle of poor security. This time NIST specifically set out to undo some of that misinformation and folklore.Now, it is nice for us to be able to write some positive things about NIST since the last time we spoke about them was negatively in the context of allowing encryption standards to be compromised by NSA influence. That said, this article will stay on-point that organisations and standards are only as good as their integrity and good-faith.