The Morning Review

Latest filing

A laptop open on a kitchen table beside a spiral notebook and a mug
A laptop open on a kitchen table beside a spiral notebook and a mug

Digital

The Password Rules You Were Trained On Were Withdrawn by the People Who Wrote Them

Change it every ninety days, one capital, one digit, one symbol. Those instructions came from a specific place, and that place reversed them years ago.

Words
985
Written by
Tobias Renfrew
Filed

Almost everyone who has held a job in the last twenty years believes a short set of things about passwords: that a symbol makes one strong, that changing it every quarter keeps it safe, and that length past a dozen characters is a nicety rather than the main event. Each of those beliefs was installed by a system that demanded it, and each has since been reversed by the same institutions that put it there. The reversal is not a technicality or a fashion. It is an admission that the old rules made accounts less safe, and following how that happened is the shortest route to habits you will actually keep.

Where the Composition Rules Came From, and Why They Made Sense

The rules about capitals and punctuation were a reasonable answer to a real problem in an era when the main threat was somebody guessing a password by hand or with a modest dictionary of common words. Force a symbol into the middle of it and the dictionary stops working, and force a change every quarter and a stolen credential has a limited shelf life. What changed afterward was the shape of the attack rather than the arithmetic behind it, since attackers stopped working through a login screen that could slow them down and started stealing whole password databases, testing millions of candidates offline at speeds no login screen ever imposed. Against that machine a symbol buys almost nothing, and every additional character multiplies the space it has to search.

What Quarterly Expiry Did to the People Subject to It

The larger failure was behavioral, and it was visible to anyone who ever walked past a colleague's monitor at the end of a quarter. Ninety day expiry produces a predictable sequence, so Spring2023 becomes Summer2023 becomes Autumn2023, the digit increments and the symbol migrates to the end. None of that is laziness. A person is being asked to invent and memorize four new secrets a year across several dozen systems, and they solve it the only way a human being can, by finding a pattern and reusing it. An attacker holding one old password can then guess the next without doing any real work, which means the control converted a single strong credential into a family of related weak ones.

The Guidance That Replaced It, and the Word Doing the Work

Federal digital identity guidance, which the National Institute of Standards and Technology maintains and makes public through its standards pages, now points close to the opposite of what most of us were trained on. Length beats composition. Do not impose periodic expiry without a reason. Do check a new password against lists of credentials already known to be exposed and refuse those outright. Do accept long passphrases and stop silently truncating them at sixteen characters, which is a limitation of old storage rather than a security measure of any kind.

The word carrying the weight there is reason. Passwords still get changed, but on an event rather than on a calendar: a breach notice naming a service you use, a shared login after somebody leaves the business, a sign-in from a place you have never been. Changing on evidence is useful and changing on a schedule is theater that makes the next password easier to guess than the last one. The length recommendation is the part people resist hardest, because a passphrase of ordinary words looks weak to an eye trained on dollar signs, and the arithmetic disagrees with the eye.

Why Your Bank Still Asks for a Symbol

If the guidance turned years ago, the obvious question is why so many systems still demand punctuation and expire you every quarter, and none of the three answers is about security. The first is that the rule sits inside software written a long time ago, and rebuilding an authentication system is an expensive project with no visible benefit to the person approving the budget. The second is compliance inertia, since internal policies and vendor questionnaires were drafted against the old advice, and an auditor working from a checklist marks you down for removing a control even where removal is the correct move.

The third is simply that nobody has ever been criticized for excessive caution about passwords, so leaving the setting alone is the safe institutional choice. This matters to you in exactly one way. When a system forces a quarterly change, do not fight it with a sequence you can remember. Let a password manager generate something unrelated to the previous entry and carry the memory burden on your behalf, because the entire harm of forced rotation came from human beings trying to hold the pattern in their heads.

Three Habits Worth Building at Home

Make the handful of passwords you type by hand long rather than clever, since four or five unrelated words you can picture will outlast anything with punctuation in it and you will not resent typing it twice a day. Stop reusing the important ones, because reuse is the mechanism behind nearly every account takeover an ordinary person experiences: one service is breached and the same pair gets tried everywhere else within days. Then turn on a second factor for email before anything else, since email is the master key that every reset link is delivered to.

One piece of the old advice survived intact, which is that you should never leave a password where somebody standing in the room can read it. That rule is more achievable now than it was, precisely because you are no longer being asked to hold a dozen rotating variants in your head at once. If a spreadsheet of quarterly variants still exists somewhere on your machine, replacing it with a small number of long passphrases and a second factor on your email is an evening's work, and it is the last evening most of those accounts will ever ask you for.

Tobias Renfrew

Tobias covers complaints, claims, and the paths open once something has gone wrong.

Also in this issue

  1. The Garden Bill You Get in Year Two, and How to Price It Before You Plant

    Most landscaping quotes price the build and stay silent on the upkeep. Here is how to work out the recurring number yourself, before the design is locked in.

  2. First Claim Denial Landed on Your Desk? The Five Checks, in the Order They Matter

    A denial letter is not a verdict. Here is what to read first, why the appeal ladder is built the way it is, and the sequence that keeps your rights open.

  3. Picking a Roof Material? The Bills That Show Up Years After the Crew Leaves

    Roofing materials are sold on price per square and a warranty number. The consequences arrive later, in insurance renewals, gutter work, attic heat and what a buyer's inspector writes down.

  4. Pricing a Grave Marker Ten Years On, and Which Line Items You Can Still Say No To

    A monument quote is four or five separate charges wearing one number. Here is how the same purchase looked a decade ago, and where a buyer's leverage sits now.