• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechPasswords

Experts Say We Can Finally Ditch Those Stupid Password Rules

By
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
By
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
May 11, 2017, 7:45 AM ET

Good news: cyber-security experts have reached the same conclusion as the rest of us when it comes to passwords—current rules are annoying and ineffective.

According to National Institute of Standards and Technology (NIST), it’s time to ditch the current practice of forcing people to randomly change their passwords every few months. Meanwhile, the federal agency also said there’s no evidence that requiring people to include numbers and special characters is worthwhile.

In other words, we may soon be spared the task of coming up with a password like MickeyMou$e1! and then having to change it a month later.

NIST published these findings on Tuesday in draft guidelines that will help determine the best security practices in government departments and in many corporate IT shops.

Get Data Sheet, Fortune’s technology newsletter.

While the agency document is written in turgid bureaucrat-speak, the ideas it proposes carry a lot of common sense and are likely to make life more difficult for hackers. For instance, the report points out that people respond to demands for special password characters with very predictable responses.

“Everyone knows that an exclamation point is a 1, or an I, or the last character of a password. $ is an S or a 5. If we use these well-known tricks, we aren’t fooling any adversary. We are simply fooling the database that stores passwords into thinking the user did something good,” Paul Grassi, one of the NIST report authors, told CSO Online.

Instead, NIST proposes a different security measure: allowing people to use passwords of their choosing (no more “8 characters with an upper case letter and a symbol”) but subject to a blacklist of terms that are easier to guess for hackers. Specifically, in the words of the guidelines, here is what should be off-limits:

  • Passwords obtained from previous breach corpuses.
  • Dictionary words.
  • Repetitive or sequential characters (e.g. ‘aaaaaa’, ‘1234abcd’).
  • Context specific words, such as the name of the service, the username, and derivatives thereof

NIST’s recommendation is also consistent with other recent research that suggests the best advice for choosing a password is to choose a long one like “iwanttodriveaTesla.” The benefits are that a long string of text letters is very hard for hackers to crack while also being easy for the user to remember.

As for changing passwords, NIST says system administrators “should not require memorized secrets to be changed arbitrarily (e.g., periodically)” but only in if the user asks to change it, or if there is evidence of compromise.

Meanwhile, the NIST report also offers supports the general trend in favor of multi-factor authentication—using an external token or even a hardware device (like these Yubico keys profiled in Fortune) to confirm a user’s identify and increase security.

So will all this make us safer? Probably. But other experts say companies must take account of their users when developing security solutions. According to Tom Kemp, the CEO of identity management firm Centrify, password requirements should change depending on whether the login is for a customer or for a key IT employee who has “the keys to the kingdom.”

About the Author
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Fortune, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

Latest in Tech

LawAmazon
Amazon is cutting checks to millions of customers as part of a $2.5 billion FTC settlement. Here’s who qualifies and how to get paid
By Sydney LakeJanuary 6, 2026
11 minutes ago
InvestingU.S. economy
Ray Dalio says AI is in ‘the early stages of a bubble,’ so watch out for 2026
By Tristan BoveJanuary 6, 2026
28 minutes ago
musk
AISocial Media
Elon Musk’s Grok chatbot draws global backlash for generating sexualized images of women and children without consent
By Kelvin Chan and The Associated PressJanuary 6, 2026
42 minutes ago
Databricks CEO Ali Ghodsi speaking on stage at a Fortune tech conference.
AIEye on AI
Want AI agents to work better? Improve the way they retrieve information, Databricks says
By Jeremy KahnJanuary 6, 2026
56 minutes ago
C-SuiteSamsung
Why one of the world’s most qualified chief design officers calls Samsung his ‘dream job’
By Nicholas GordonJanuary 6, 2026
2 hours ago
AINvidia
A year ago, Nvidia’s Jensen Huang said the ‘ChatGPT moment’ for robotics was around the corner. Now he says it’s ‘nearly here.’ But is it?
By Sharon GoldmanJanuary 6, 2026
3 hours ago

Most Popular

placeholder alt text
Personal Finance
Janet Yellen warns the $38 trillion national debt is testing a red line economists have feared for decades
By Eva RoytburgJanuary 5, 2026
1 day ago
placeholder alt text
AI
Experienced software developers assumed AI would save them a chunk of time. But in one experiment, their tasks took 20% longer
By Sasha RogelbergJanuary 5, 2026
1 day ago
placeholder alt text
Energy
‘Big Short’ investor Michael Burry says toppling of Venezuela’s Maduro will weaken Russia’s global standing as its oil ‘just became less important’
By Marco Quiroz-GutierrezJanuary 5, 2026
24 hours ago
placeholder alt text
Success
Blackstone exec says elite Ivy League degrees aren’t good enough—new analysts need to 'work harder' and be nice 
By Ashley LutzJanuary 5, 2026
1 day ago
placeholder alt text
Economy
Under Biden, America got 150 countries to agree a 15% global corporate tax. Under Trump, America gets an exemption
By Fatima Hussein and The Associated PressJanuary 5, 2026
21 hours ago
placeholder alt text
Personal Finance
Current price of silver as of Monday, January 5, 2026
By Joseph HostetlerJanuary 5, 2026
1 day ago

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.