I'm going to start with a myth that refuses to die: that a password like P@ssw0rd! is strong because it has uppercase, lowercase, a number, and a symbol. It's not. It's weak. And the advice that produced it—forced complexity and regular password changes—is officially obsolete. I'll explain why, and what you should do instead.
Isn't a complex password with symbols and numbers the strongest?
No. Length matters far more than complexity. A long passphrase of unrelated words is both stronger and easier to remember. The UK's National Cyber Security Centre recommends three random words—like 'applenemobiro'—and warns that letter-to-symbol swaps such as 'o' to '0' add little strength. The NCSC also says to avoid passwords based on birthdays, sports teams, or pet names, since those details are often visible on social media.
CISA recommends passwords of at least 16 characters—'longer is stronger'—and suggests passphrases made of 4–7 unrelated words, which may include spaces. So instead of Tr0ub4dor&3, try correct horse battery staple moon. It's longer, easier to type, and vastly harder to crack.
Should I change my passwords every 90 days?
No. That old rule is counterproductive. NIST's digital identity guidelines forbid mandatory periodic password changes and forced complexity rules. Why? Because they lead to predictable patterns: Summer2024! becomes Fall2024!. The real defense is uniqueness—never reuse a password across sites—and length. If you suspect a breach, change it immediately, but don't rotate on a calendar.
How long should my password be, really?
It depends on whether it's your only authentication factor. NIST requires passwords used alone to be at least 15 characters; when used as part of multi-factor authentication, they can be shorter but still at least 8 characters. CISA says at least 16 characters. NSA and CISA list easily crackable passwords shorter than 15 characters as one of the top ten network misconfigurations. My rule: aim for 16+ characters for anything important, and use a password manager to generate and store them so you don't have to remember.
Is it okay to write my password down?
The NCSC says writing a password down is acceptable if kept somewhere safe. But I think that's a last resort. A password manager is better: it generates and stores unique, random passwords for every account, eliminating reuse. If you must write one down, keep it in a locked drawer, not on a sticky note under your keyboard.
What about multi-factor authentication—doesn't that make passwords obsolete?
MFA is essential, but it's not a free pass. Microsoft says enabling MFA can block over 99.9 percent of account compromise attacks. Yet traditional MFA can be bypassed by phishing, push bombing, SS7 vulnerabilities, and SIM swapping. CISA ranks phishing-resistant MFA—FIDO/WebAuthn and PKI-based—as the gold standard. So use an authenticator app or a hardware security key rather than SMS codes, which are vulnerable to SIM swapping. And yes, enable MFA on every account that supports it, starting with email, banking, and cloud accounts.
How do I know if my password has already been leaked?
Check. Have I Been Pwned is a free service run since 2013 by Troy Hunt that lets you check whether an email address or username has appeared in a known data breach. It was created after the Adobe breach because the same accounts kept appearing exposed, often with the same passwords. CISA recommends checking for breached credentials and rotating any compromised passwords. If your email shows up, change that password everywhere you've used it—and if you reused it, change it on every site.
What's the single most important thing to remember?
Stop reusing passwords. That's it. Reuse enables password-spray and credential-stuffing attacks, where attackers try common or previously breached passwords against many accounts. A password manager makes unique passwords effortless. If you do nothing else today, install one, generate a 16+ character passphrase for your email, and enable MFA on that account. That combination—long, unique, and backed by MFA—is your best defense.
Sources
- CISA (Use Strong Passwords) - https://www.cisa.gov/secure-our-world/use-strong-passwords
- NIST SP 800-63B - https://pages.nist.gov/800-63-4/sp800-63b.html
- NCSC (Three Random Words) - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
- Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
- Have I Been Pwned (About) - https://haveibeenpwned.com/About
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!