Summary

There’s a decent chance you follow at least one password rule you never consciously signed up for. Toss in a capital letter, add a number, sprinkle in a special character, and preferably jam them together in a way that looks sufficiently hostile to human memory. If you’ve ever worked somewhere with mandatory password resets, you’ve probably gotten into a situation where you changed Password!7 to Password!8 and everyone involved agreed to call that security. A lot of that password orthodoxy can be traced back to guidance NIST started developing in the early 2000s. Bill Burr, then a manager at the National Institute of Standards and Technology, helped shape an appendix that went on to influence password policies across the board. Years later, he admitted publicly that some of the advice hadn’t played out the way he expected. Funny enough, the original document had already noticed some of the exact human habits that would eventually make those rules backfire. An 8-page appendix helped set the password rules Bill Burr drafted it without the password data we have now Burr worked on the guidance in 2003, and NIST published Special Publication 800-63 [PDF] in June 2004. The full document was a much broader federal authentication standard, credited to Burr, Donna Dodson, and W. Timothy Polk, with Burr becoming especially associated with the password-focused Appendix A. That section spent about eight pages trying to answer a deceptively simple question: how hard would user-created passwords be to guess? The catch was that NIST didn’t have much real-world evidence showing how people actually behaved under different password rules. The appendix said as much. Its estimates unpredictability. That model produced advice that will look painfully familiar to anyone who has ever fought with a corporate password box. One example described an eight-character password policy requiring uppercase and lowercase letters, a number, and a special character. The document also assigned an estimated entropy bonus to composition rules, which gave institutions a neat mathematical reason to believe that forcing people to mix character types would buy them meaningful extra security. The guidance was written for federal authentication systems, though NIST allowed private organizations to adopt it voluntarily. The ideas spread far beyond that original audience. Businesses, universities, websites, and IT departments embraced similar complexity rules until password creation turned into the same tiny obstacle course most of us still recognize today. The rules made people wonderfully predictable Humans found the easiest way through every requirement Burr’s appendix already understood that people would game the rules. It warned that users forced to add capital letters and symbols would probably do it in the most predictable ways possible. The capital letter would go at the front, punctuation would get parked at the end, and swaps like ”$” for “s” would show up again and again. It also pointed out that passwords designed to look highly random could become so annoying to remember that people would start writing them down somewhere handy. Even with those warnings sitting right there in the document, the guidance still gave composition rules extra security credit. In practice, people learned the same handful of moves, so “password” became “Password1!” and the supposedly stronger result followed a pattern attackers could build straight into their guessing tools. If you want a practical sense of what that means, password crackers can work through likely guesses surprisingly efficiently. The appendix had basically predicted the behavior and still assigned an entropy bonus to rules that encouraged it. Scheduled password changes piled on another layer of friction. The archived 2004 appendix doesn’t actually prescribe the infamous 90-day reset rule. However, it does discuss password lifetimes in worked examples, and Burr’s advice later became closely tied to regular password changes. Once expiration policies became common, users reacted the way anyone would when asked to dream up another password in the middle of a workday, nudging the old one forward. That’s a big part of why changing your password every 90 days is now considered outdated advice. If an attacker already knew your old password, changing Pa55word!1 to Pa55word!2 wouldn’t slow them down much. Later research [PDF] on password reuse and modification found that people tend to make these changes in highly predictable ways, giving attackers plenty of structure to work with. The end result was a set of rules that made passwords more annoying for users while leaving attackers with a surprisingly legible playbook. Burr eventually admitted the advice had backfired By 2017, he wanted parts of it gone too By August 2017, Burr had retired, and he was pretty candid with The Wall Street Journal about how the guidance had aged. He said he regretted much of what he had done and acknowledged that the extra complexity forced on users had bought far less security than he expected. Much of what I did I now regret It’s tempting to turn that into a neat story about one guy realizing he sent the internet down the wrong path, but the history is messier than that. The original appendix was packed with caveats, described its entropy estimates as rough, and even predicted some of the shortcuts people would take to circumvent the rules. The bigger mistake was giving composition requirements enough credit that organizations could harden them into rigid policy. By 2017, researchers had access to years of leaked passwords and datasets large enough to show how people actually create, reuse, and tweak passwords in the real world. That gave the field what Burr’s appendix openly admitted it was missing in 2004: a much clearer view of human behavior once password rules left the page and met actual users. NIST eventually threw out the familiar recipe The current rules barely resemble the ones people remember The 2017 rewrite, NIST SP 800-63B, took password advice in a noticeably different direction. Mandatory requirements mixing uppercase letters, lowercase letters, numbers, and symbols were gone, along with routine password expiration unless there was evidence that the password had been compromised. NIST also screening new choices against lists of predictable or previously breached passwords. That last part is something you can do yourself, too. Several services can check whether your password has already appeared in a data breach, including Have I Been Pwned and password-checking tools built into larger platforms. That change stuck. NIST replaced the 2017 edition with SP 800-63B-4 in 2025, and the current guidance carries the same basic philosophy forward. Services that follow it are advised to avoid character-composition rules and skip periodic resets unless there is evidence of compromise. When a password is the only authentication factor, the minimum length is now 15 characters, and services should support passwords of at least 64 characters. Hence, users have enough room for longer passphrases. Length now carries much more weight than making people complete a character-class scavenger hunt every time they create a login. You can use a longer passphrase made from several random words when you need something memorable. At the same time, a password manager can generate a unique random password instead of making you invent one yourself. Old password habits have ridiculous staying power Those old rules still look pretty normal. Plenty of sign-up forms still haven’t caught up. A 2023 study [PDF] of more than 20,000 websites found that 15% still enforced character-composition rules that modern password guidance no longer recommends. Capital letters and symbols obviously still expand the number of possible passwords. The problem was turning those ingredients into rigid rules for actual humans, who tend to answer annoying constraints with shortcuts, patterns, and whatever gets the form to stop yelling at them. NIST’s current guidance reflects that lesson pretty clearly. Getting every login screen, IT department, and corporate security policy to catch up has been the much slower part.

By Oluwademilade Afolabi

Original Article