Skip to main content

Man responsible for strong password requirements regrets his 2003 guidelines

The man responsible for your requirement to use a combination of lower-case letters, upper-case letters, numbers, and symbols in passwords at least eight characters long is now regretting his advice. Former National Institute of Standards and Technology manager Bill Burr recently admitted in an interview with The Wall Street Journal that his 2003 document about crafting strong passwords and changing them every 90 days was somewhat off the mark.

At the time, he said that users will choose an easily remembered, easily guessed password, and likely one stemming from a batch of “a few thousand commonly chosen passwords.” In turn, hackers trying to gain access to user accounts, computers, and so on would try the most likely chosen passwords first. But even though services would reject specific passwords given their common use, Burr suggested a more secure alternative.

Recommended Videos

On page 52 of the 2003 document, he clearly states that systems should rely on a password of eight characters or more that are selected from an alphabet of 94 printable characters. This password should also include at least one upper case letter, one lower case letter, one number, and one special character. Systems should even rely on a dictionary that prevents users from including familiar words and using their login name as the password too.

Please enable Javascript to view this content

The problem with this method is that users tend to have patterns when creating a password. For instance, they may take a familiar word, such as “password,” and alter it slightly to meet the requirements. The result could be something like P@zzwurd2017, which isn’t all that original, and something we conjured up in a matter of seconds.

Right now, systems give users a thumbs-up when they follow the current standard and even provide a visual measurement tool indicating the password’s strength against hacking. But then users are requested/forced to change their password every 90 days, thus they may use the same base word, but alter the character usage to please the update process (such as P@ssw0rd2K17).

When the guidelines were created in 2003, they were not based on collected data. System administrators would not cough up any passwords for examination, thus Burr turned to a whitepaper published in the 1980s — long before the general American population purchased a modem and jumped onto the world wide web using Netscape or America Online.

Fast forward to 2017, and the National Institute of Standards and Technology provides new guidelines for systems to follow. Authored by technical adviser Paul Grassi, it tosses out much of what Burr established years ago. But Grazzi admits that Burr’s system lasted for 14 years, and hopes that his revised password ruleset lasts just as long. He suggests that systems remove the 90-day password refresh and the requirement for special characters.

Ultimately, the best practice for everyone is to throw out familiar, easily linked ideas, such as the name of your favorite movie or pet. Instead, create a phrase of words that doesn’t make much sense, and does not include spaces. Password managers like LastPass are helpful too when you are required to remember a multitude of unique passwords across dozens of services.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
OpenAI showing a ‘very dangerous mentality’ regarding safety, expert warns
ChatGPT and OpenAI logos.

An AI expert has accused OpenAI of rewriting its history and being overly dismissive of safety concerns.

Former OpenAI policy researcher Miles Brundage criticized the company's recent safety and alignment document published this week. The document describes OpenAI as striving for artificial general intelligence (AGI) in many small steps, rather than making "one giant leap," saying that the process of iterative deployment will allow it to catch safety issues and examine the potential for misuse of AI at each stage.

Read more
M3 Ultra vs. M4 Max: Which is better? Benchmarks can’t tell either
2025 Mac Studio

Apple surprised us with its announcement of the new Mac Studio this week, and confused us with its chip choices -- the M4 Max and the M3 Ultra. It's hard enough to tell which chip is more powerful just from their names, but according to early benchmarks, it's also hard to tell from their CPU performance.

https://x.com/VadimYuryev/status/1897849477706481701?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1897849477706481701%7Ctwgr%5E8073e41e643559d3c995c3a698fc2b5523a61222%7Ctwcon%5Es1_&ref_url=https%3A%2F%2F9to5mac.com%2F2025%2F03%2F06%2Fm3-ultra-m4-max-chip-benchmark%2F

Read more
AMD’s RX 9070 XT could soon cost a lot more than it does now
An Asus RX 9070 XT TUF GPU.

After the way Nvidia's RTX 50-series ended up being called a "paper launch," many breathed a sigh of relief when AMD's RX 9000 series appeared on the shelves in much larger quantities. However, once this initial shipment is sold, AMD could face the same problem as the rest of the best graphics cards: Price hikes, price hikes everywhere.

The cards officially hit the shelves yesterday, and many were spotted far above the recommended list price (MSRP), with some overclocked models priced at up to $250 more than the $600 starting price. However, AMD spoke several times about working with its partners to ensure wide availability at MSRP, and indeed, many retailers had some models up for sale. Those MSRP cards were only around for a short time, though, and they might never come back, according to retailers.

Read more