MAR 19, 2024 /

Time to relearn all your password rules

For just about any online service you’d care to name, you’re going to be requested to set up a password in order to securely access those services. This may be for a relatively trivial reason, such as one-time access to a site you’re not sure you’re going to use regularly, or something far more serious such as your online banking.

Either way, you’ve probably been hit by a set of password rules that required you to, generally, pick a unique password (always important) with at least one capital letter and one number as part of the combination. There’s a reason why those rules have permeated across the internet which can be traced back to a US security document from 2003, which laid out the (at the time) understood best practice for password creation.

There’s just one problem. The rules that were laid down then were built on both a limited understanding of passwords, and an even more limited subset of “bad” passwords to work from, most of which dated from the 1980s. They recommended, amongst other things, that passwords should be regularly changed, as frequently as every 90 days.

For many of us, this has led to really lax practices, such as re-using passwords across multiple sites, or using really simple ciphers such as appending a number (usually a 1) to the end of a new password to make it easy to remember. Many folks adopted the use of numbers to replace letters, so that “e” becomes “3”, “A” becomes “4” and “O” becomes “0”, for example.

There’s a big problem here, because that creates a recipe for passwords, and it’s one that, especially as processing power has grown, has been ever easier for computers to crack. The author of the original password document now states that they’re not terribly suitable for human beings to use, because they promote passwords that are hard for humans to remember, but easy for hackers to crack.

So what’s the solution? The new rules being proposed change up the way that traditional passwords were thought of.

Out with mandatory numbers, because we’re (generally) lazy and always tend to append them to the ends of our passwords.

Out too, with forced changes of passwords, because that should only be necessary if there’s a known breach of a given service or site.

Users should be encouraged to use passphrases, because you can generally remember a phrase much more easily than a random jumble of letters, whether it’s a song lyric, a poetry phrase or simply a string of words that you happen to like and can find memorable.

Of course, you can still mix it up a little and, for example, use methods such as Diceware, where you roll dice to pick words from a random list, or use acronyms based on the lyrics of your favourite song.

The new rules also stipulate password lengths of up to 64 characters, but before you panic at that length, they also suggest allowing password fields to support pasting in passwords. That means they should work with password managers such as Dashlane, 1Password or Keepass, and that’s good news if you have many passwords to remember, as so many of us do.

With a decent password management app, all you need is one decent passphrase or password, and then you can let the app do the calculations and creation of new passwords for you on the fly, unlocking the app with your master password and pasting in new passwords as needed.

Photo of Alex Kidman
Alex Kidman
A multi-award winning journalist, Alex has written about consumer technology for over 20 years. He has written and edited for virtually every Australian tech publication including Gizmodo, CNET, PC Magazine, Kotaku and more.