MCO eComms Compliance leverages best practices for password policies as recommended by NIST SP 800-63B (Digital Identity Guidelines: Authentication & Lifecycle Management). One such recommendation is for providers to compare passwords against a list of values commonly used, expected, or compromised.
Fairwords maintains this list and will notify users attempting to create or change their password if a match occurs. The application will not allow users to create a password that matches the current disallowed password list.
Disallowed passwords include:
Common passwords obtained from past breach corpuses (e.g. password123, letmein)
Dictionary words (e.g. password, login)
Repeating or sequential characters (e.g. aaaaaa, 12345678, qwerty)
Words frequently associated with Fairwords, our products, or use cases (e.g. fairwords, guide)
The list of disallowed passwords does change over time. Therefore, a password the user is allowed to enter today may not be allowed as a user password next year. Changes to the disallowed password list will not impact existing passwords.