Are complex passwords 'out of date'?

 This information is based on newly published guidance from the US National Institute of Standards and Technology (NIST), which develops and issues guidance to help organizations protect information systems.

Are complex passwords 'out of date'? Picture 1

For years, complex passwords, combining uppercase and lowercase letters, numbers, and symbols, have been favored by experts and service providers because they are believed to make passwords harder to guess or crack through brute force attacks.

However, complex passwords are counterproductive and actually weaken security. Complex passwords encourage users to develop bad habits such as choosing simple passwords or reusing old passwords.

In its latest guidelines, NIST has encouraged using longer passwords instead of complex passwords.

The first reason is that people often have trouble remembering complex passwords, which leads them to use passwords that are easy to guess or to use the same password for multiple sites. This is exacerbated by the fact that many organizations require you to change your password every 60 to 90 days, which NIST no longer recommends.

Password strength is often measured by entropy, the number of possible combinations that can be created using the characters in the password. The higher the number of combinations, the harder the password is to crack using brute force or guessing methods.

Length plays a much larger role in the number of possible combinations than complexity. A longer password with more characters has exponentially more possible combinations.

The second reason is that long passwords with many simple words are easier to remember, ensuring users don't resort to unsafe practices like writing down passwords or reusing them.

Additionally, long passwords, due to the large number of possible combinations, are more difficult for complex algorithms to crack than short, complex passwords.

For example, changing a password from 4 digits to 6 digits increases the number of possible combinations from 10,000 to 1,000,000.

NIST recommends that users create passwords that are up to 64 characters long. A password that uses only lowercase letters and words is extremely difficult to crack, while one that includes uppercase letters and symbols becomes mathematically impossible.

4.5 ★ | 2 Vote

May be interested

  • How to fix the date #VALUE error in ExcelHow to fix the date #VALUE error in Excel
    when entering a date-related formula in excel, some people are reported with the #value error, affecting the results in excel files.
  • Instructions for scanning Wifi QR codes on iPhone are simple and easy to followInstructions for scanning Wifi QR codes on iPhone are simple and easy to follow
    knowing how to scan wifi qr codes on iphone will save you a lot of time compared to manually entering wifi passwords, especially when the passwords are highly complex. the article below will show you how to scan wifi qr codes on your iphone super simply.
  • List of easy passwords to crack in 2023, in less than a secondList of easy passwords to crack in 2023, in less than a second
    nordpass recently announced a list of easy-to-crack passwords in 2023. accordingly, easy-to-remember passwords such as p@ssw0rd, qwertyuiop or aa123456, admin are still commonly used.
  • Date and Time in C ++Date and Time in C ++
    the c ++ standard library (c ++ standard library) does not provide an appropriate date type. c ++ inherits the structure and function to manipulate date and time from c. to access functions and structures related to date and time, you will need to declare in your c ++ program.
  • Top 10 faces with the worst passwords in 2018: Second US Defense MinistryTop 10 faces with the worst passwords in 2018: Second US Defense Ministry
    below is a list of 10 individuals and organizations with the worst passwords of 2018 published by dashlane account password management service.
  • Recover passwords with free utilities (part 1)Recover passwords with free utilities (part 1)
    when using a pc or internet, you will have to memorize a lot of passwords for dialup and email accounts ... all passwords will be converted to *** and when you forget the small utilities below this will help you easily find your password.
  • How to create secure passwords on FastwordHow to create secure passwords on Fastword
    fastword helps you to create password ranges with many different random characters, helping users to have a safe and difficult-to-guess password sequence.
  • How to change time, date and month in Windows 10?How to change time, date and month in Windows 10?
    many users are still not familiar with the operation on windows 10, such as changing the system date and time on win 10. below, tipsmake.com will guide you to change the date and time on windows 10 to the time you want. like fixing windows 10 error showing wrong date and time.
  • How do websites protect your passwords?How do websites protect your passwords?
    how do websites store your passwords? how do they keep your logins secure? and what is the most secure method websites can use to track your passwords?
  • The US seeks to abandon the use of passwordsThe US seeks to abandon the use of passwords
    hackers all over the world are becoming more and more skilled in password theft, so computer technology scientists are looking to replace this computer's biggest nuisance for computer generations. next.