Why Password Advice Changed

Written by Studio AM.

Password advice has changed. Many sites once demanded a short string with a capital letter, a number, and a symbol. Current guidance puts more weight on length, uniqueness, and tools that reduce what a person must remember.

Length matters because every unpredictable character can multiply the possible strings. Symbols can enlarge that set too, but forced rules often lead people to predictable swaps, such as replacing a letter with a similar-looking number. No chart can promise one cracking time for every password. The rate depends on the password, the way a site protects it, the attacker’s equipment, and whether guesses happen online or against stolen data.

Reuse creates a different danger. If one service is breached, attackers may try the same email and password elsewhere. A unique password for each account limits that chain.

A password manager can create and store long, random passwords. Multi-factor authentication adds another check, and passkeys can avoid a shared password altogether. When a person must remember a password, a long and unusual passphrase may be easier than a short jumble. The goal is not one magic recipe. It is to make guessing difficult and one stolen secret less useful.

Questions

Choose an answer. The explanation appears after you answer.

  1. Question 1 of 4

    What is the passage mainly about?

  2. Question 2 of 4

    Why can no chart promise one cracking time for every password?

  3. Question 3 of 4

    In this passage, “unique” means

  4. Question 4 of 4

    Why does password reuse make one breach more damaging?

Score: none answered yet.

More passages

Practise reading