Black Friday Sale! 50% Off All Access

You Might Not Need Complex, Alphanumeric Passwords After All NIST now recommends using long passphrases instead of complicated alphanumeric passwords, and only refreshing them if they've been breached.

By Angela Moscaritolo

This story originally appeared on PCMag

Shutterstock

Everyone knows that creating complex, alphanumeric passwords, let alone remembering them, is pretty much the worst. Our lackluster password skills have spawned an entire password manager business.

Now it seems our troubles were perhaps for naught, and the dude who created the rules about complex passwords would like to apologize.

That man is Bill Burr, who is now 72 and retired. Almost 15 years ago, while working at the National Institute of Standards and Technology (NIST), he wrote what would basically become the bible of password management: NIST Special Publication 800-63. Appendix A. You may have never heard of it, but you're surely familiar with its mandates: passwords must be at least a certain length and include a number, upper and lowercase letters and special characters like an exclamation point or question mark, and must be changed every 90 days.

Now, Burr says that advice was a mistake. "Much of what I did I now regret," Burr tells The Wall Street Journal.

When Burr was writing the publication, he didn't have much data to go by and was being pressured to come up with guidance quickly, according to the Journal. For research purposes, he asked the computer admins at NIST for a peek at the passwords on their network, and they scoffed at the idea. So, to get the job done, he "leaned heavily on a white paper written in the mid-1980s," the Journal reports.

"In the end, it was probably too complicated for a lot of folks to understand very well," Burr says. "It just drives people bananas and they don't pick good passwords no matter what you do."

Fortunately, NIST Special Publication 800-63 recently received a much-needed rewrite. Gone are the rules about changing your password every 90 days and using special characters. NIST now recommends using long passphrases instead of complicated alphanumeric passwords, and only refreshing them if they've been breached.

Angela Moscaritolo has been a PCMag reporter since January 2012. 

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Living

These Are the 'Wealthiest and Safest' Places to Retire in the U.S. None of Them Are in Florida — and 2 States Swept the List.

More than 338,000 U.S. residents retired to a new home in 2023 — a 44% increase year over year.

Business News

These Are the Highest Paying Jobs Available Without a College Degree, According to a New Report

The median salaries for these positions go up to $102,420 per year.

Starting a Business

This Sommelier's 'Laughable' Idea Is Disrupting the $385 Billion Wine Industry

Kristin Olszewski, founder of Nomadica, is bringing premium wine to aluminum cans, and major retailers are taking note.

Starting a Business

He Started a Business That Surpassed $100 Million in Under 3 Years: 'Consistent Revenue Right Out of the Gate'

Ryan Close, founder and CEO of Bartesian, had run a few small businesses on the side — but none of them excited him as much as the idea for a home cocktail machine.

Business News

Is Reddit Down Again? Tens of Thousands of Users Are Reporting Issues With the Platform.

A Reddit outage has been occurring off-and-on for two days.

Business News

DOGE Leaders Elon Musk and Vivek Ramaswamy Say Mandating In-Person Work Would Make 'a Wave' of Federal Employees Quit

The two published an op-ed outlining their goals for their new department, including workforce reductions.