# Database Concepts and Design — Stale course audit

- URL: https://getstale.tech/run/web_20260504T210835Z
- Target role: Data Engineer
- Course focus: Relational Database Fundamentals — Design, Sql, Internals
- Audit date: 2026-05-04T21:08:35Z
- Verified findings: 2
- Structured data: https://getstale.tech/run/web_20260504T210835Z.json

## Findings

### 1. Outdated (medium severity)

**Location:** Week 10 - Database Views and Authorization_.pdf page 9

**What the slide says:**

> Strong password policies prevent unauthorized user access: ... Implement password expiration and lockout mechanisms

**Primary source:** https://pages.nist.gov/800-63-4/sp800-63b.html (verified)

> Verifiers and CSPs SHALL NOT require subscribers to change passwords periodically.

**What to learn instead:** Drop the periodic password-expiration recommendation. Per NIST SP 800-63B (current revision -4, August 2025), verifiers SHALL force a password change only if there is evidence the authenticator has been compromised. Pair long passwords (≥15 chars), screening against breach corpus blocklists, salted+hashed storage with a memory-hard KDF, rate-limiting on failed attempts, and phishing-resistant MFA (e.g., WebAuthn/FIDO2) instead of forced rotation.

### 2. Outdated (low severity)

**Location:** Week 10 - Database Views and Authorization_.pdf page 9

**What the slide says:**

> Use complex passwords and multi-factor authentication (MFA).

**Primary source:** https://pages.nist.gov/800-63-4/sp800-63b.html (verified)

> Other composition requirements for passwords SHALL NOT be imposed.

**What to learn instead:** Drop 'complex passwords' guidance based on character-class composition rules (mixed case, digits, symbols). Per NIST SP 800-63B-4 §3.1.1, composition rules SHALL NOT be imposed; instead require a 15-character minimum (8 with MFA), allow up to 64+ characters including spaces and Unicode, screen prospective passwords against a blocklist of breached/common passwords, and keep the MFA recommendation.

## Market fit

No in-scope gaps: this single-node relational-fundamentals curriculum teaches the one ml_data skill it shares with the market (SQL) thoroughly, while every other ≥30%-demanded skill — Python and the pandas/numpy/scikit-learn/pytorch/tensorflow/hugging-face stack, git/docker/kubernetes/aws, and the distributed/NoSQL data layer (bigquery, snowflake, spark, vector databases, dbt, airflow, ray) — is excluded by Rule 3 (cross-domain) or by the course's depth bound (which explicitly rules out distributed databases and NoSQL engines), so there is no partially-covered topic to extend.

## Recommended topics

No prescriptions issued. The Market-fit agent surfaced zero in-scope gaps (gap_count: 0) for this single-node relational-fundamentals course against the ml_data role. The one skill the curriculum and the market share — SQL — is already taught thoroughly across Week 8 (Basic Query), Week 9 (Complex Query), Week 10 (Views/Authorization), and Week 11 (Relational Algebra), and every other ≥30%-demanded ml_data skill (Python, pandas, NumPy, scikit-learn, PyTorch, TensorFlow, Hugging Face, git, Docker, Kubernetes, AWS, dbt, Airflow, Spark, Ray, BigQuery, Snowflake, vector databases, RAG) is either a cross-domain language/tooling concern or sits beyond the course's stated depth bound (which explicitly excludes distributed databases, NoSQL engines, query-optimizer internals, and concurrency-control algorithms).

---
Produced by Stale (https://getstale.tech). Request a course audit: https://getstale.tech/request-audit
