HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 15:36 CET 37 dossiers MITRE ATT&CK mapping

Editorial explainer · official sourcesmedium

The password rules we were taught are wrong

The ninety-day password change, the mandatory special character, the capital letter forced in for its own sake: these are the rules a generation learned to make passwords by. And they are the same ones NIST — the very body that helped spread them — now recommends abandoning. Revision 4 of SP 800-63B flips the perspective: length matters, not artificial complexity. An explainer on what changed and why it is a matter of culture before technology.

The habits no one updated

There is a part of security that lives on automatic gestures, repeated because "it has always been done this way". Passwords are the textbook case. Many organisations still impose rotation every three months, demand at least a number, a capital and a symbol, and are convinced this makes accounts safer. The problem is that whoever wrote those rules changed their mind, and long ago.

NIST — the US National Institute of Standards and Technology, a reference well beyond the United States — in revision 4 of its SP 800-63B guidance puts down in black and white a set of recommendations that sound heretical only because we learned the opposite. They are not opinions: they are the technical standard many build their policies on.

What the standard actually says

Three points sum up the change. First: length beats complexity. The standard asks for at least 15 characters for a password used as a single factor, and generally invites accepting long phrases — passphrases — instead of short, contorted strings. A phrase you remember and do not write on a sticky note is worth more than "P@ss1!" reused everywhere.

15
minimum characters
for a password used on its own, per rev. 4
0
forced rotations
no periodic expiry without a concrete reason
yes
block known passwords
screen against lists of already-breached ones

Second: no periodic expiry. NIST explicitly says not to force changes at fixed intervals, and to require one only when there is evidence of compromise. The reason is counterintuitive but solid: forced to change constantly, users make small predictable variations — the same password with a rising number — and the result is weaker, not stronger. Third: block passwords already found in known breaches. The standard asks that new passwords be checked against lists of common and compromised ones, and refused. That is where the real game is played, not in the mandatory exclamation mark.

Why it is culture, not just configuration

One could file all this as a matter of settings to change in a panel. But the knot is cultural. The old rules survive because they seem strict, and apparent strictness reassures: if I make people suffer a little, I think I have made them secure. NIST's revision dismantles precisely this equation. Security is not how annoying the rule is, it is how effective — and some annoying rules are, in practice, counterproductive.

A couple of honest clarifications. These recommendations concern how to manage passwords, but the password alone remains the weak factor: multi-factor authentication, ideally phishing-resistant, is the other piece no standard makes optional. And adopting the new rules does not mean relaxing, it means moving the effort where it counts: length, password managers so you do not reuse them, blocking those already breached. The source to read in full is NIST's SP 800-63B; the rest is to stop defending habits their own inventors have already moved past.

More dossiers