Issue 16Nothing here is sponsored

The Steady Report

Useful detail on decisions that are hard to reverse.


FileTech

Standards Bodies Have Quietly Withdrawn Most of the Password Advice You Learned a Decade Ago

Forced expiration, mandatory character classes and security questions were standard guidance and are now discouraged, for reasons that hold up well.

  • ByRosalind Ntuli
  • Cut6/9/26
  • Length946 words
  • Read4 min
A notebook and a small hardware security key resting beside a closed laptop on a wooden table
A notebook and a small hardware security key resting beside a closed laptop on a wooden table

Most people learned their password habits from an employer login screen sometime in the late two thousands, and most of those habits are now discouraged by the same institutions that originally required them. This is not a fashion cycle. The rules were withdrawn because evidence accumulated that they made human behavior worse, and understanding why they failed is considerably more useful than memorizing whatever replaced them. Midyear is a reasonable moment to act on it, before summer travel puts household accounts onto hotel networks and unfamiliar devices, which is where the weak ones tend to be tested.

Three Rules That Were Retired

Forced expiration every ninety days is the first and the most widely mourned. Users responded to mandatory rotation by making small predictable changes, incrementing a number or shifting a symbol one place, which is trivially guessable once any single version is known, so the rule converted one compromised password into a family of them. Expiration is now recommended only where there is actual evidence of compromise, which is the situation in which changing a password accomplishes something rather than merely inconveniencing the person who has to invent the next one.

Mandatory character classes are the second. Requiring an uppercase letter, a number and a symbol pushed people toward a narrow band of patterns, a capital at the beginning, a digit at the end, a symbol substituted for a letter it resembles, and attack software knows every one of those patterns intimately. The requirement added far less unpredictability than its arithmetic suggested. Security questions are the third, since a mother maiden name or a first school is a shared secret whose answer is frequently public, guessable, or sitting in a breach file already.

What Replaced Them

Four principles took their place, in rough order of how much they matter. Length beats complexity, because a long passphrase of unrelated words is both harder to attack and easier to remember than a short string of substituted characters. Uniqueness matters more than either, since the single most consequential property of a password is being used in exactly one place, and reuse is the mechanism behind most account takeovers: a password stolen from a forgotten retailer gets tried automatically, at scale, against the email address it was registered with.

Multi-factor authentication is third, with the caveat that a texted code can be diverted by anybody who persuades a carrier to move a phone number to a new device. That makes an app-generated code or a physical key the stronger form while a texted code remains far better than nothing. Screening against known compromised passwords is fourth and is a more direct control than any composition rule. Nearly all of this traces back to what the National Institute of Standards and Technology publishes on digital identity, which employers copy because it is free and defensible to an auditor.

Where Passkeys Currently Stand

Passkeys replace the password with a cryptographic key pair held on a device and unlocked by that device own biometric or PIN, so the private key never leaves the hardware and nothing reusable is transmitted anywhere, which removes both the phishing risk and the breach reuse risk in a single step. Adoption remains uneven. Major platforms and a growing number of banks and retailers support them, though many services offer them alongside a password rather than instead of one, which limits the benefit because the password is still a way in.

Recovery is the other open question, since passkeys are typically synchronized through a platform account and losing access to that account becomes the new single point of failure, which is a different shape of problem rather than a smaller one. The reasonable position for a household is to adopt passkeys wherever a service offers them, keep a password manager for everything else, and pay real attention to the recovery path for whichever platform account is holding the keys, because that is now the account everything else depends on.

What Did Not Change

Three pieces of the old advice survived the revision entirely intact and are worth separating from the parts that were withdrawn. Do not share a password and do not use a shared account where individual ones are available, because a shared credential removes any ability to tell who did what, and where a household or a small business genuinely needs shared access most managers support it properly, with individual identities sitting behind a shared vault. That distinction matters more as soon as more than two people are involved.

Treat any unsolicited message asking you to sign in as hostile until proven otherwise, and reach the service by typing its address yourself rather than following a link, since phishing remains the most common route into an account and works against strong passwords exactly as well as against weak ones. That is why the second factor carries so much of the load. And lock the device, because a password of any length protects nothing on a machine left open on a desk or a phone left face up on a cafe table.

The Half Hour Version

A full audit will not get done and is not necessary, while a short one will and is. Start with the accounts that can reset the others, meaning the primary email address, the phone carrier account and the password manager itself, and give each a long unique passphrase and the strongest second factor available, then check that the recovery email and phone number on file are still ones you control, which is where old accounts most often fail quietly. Move next to anything holding money, then to whatever was set up before the manager existed, since that is where reuse survives.


Elsewhere in the pile

  1. 01Formed the Company and Filed Nothing Since? The Obligations That Keep an LLC in Existence
  2. 02An Attic Air Handler Makes Gallons of Water a Day and One Pipe Carries It Away
  3. 03Which Documents Are Impossible to Get Once a Dispute Has Already Turned Contentious?
  4. 04Bookkeeper, Enrolled Agent or CPA: Which One You Need Is a Question About the Year