The National Institute of Standards and Technology (NIST) has updated its Digital Identity Guidelines, which serve as a set of best practices for password security across private sector industries. The new guidelines recommend that passwords should be easy to remember but hard to guess, and that usability and security go hand-in-hand. The guidance also includes standards for multi-factor authentication and caveats on the use of biometrics as factors, supporting only their “limited use” in authentication. NIST recommends using a minimum of eight characters and a maximum length of at least 64 characters, using all special characters, and prohibiting commonly-used, expected, or compromised passwords.