The Man Who Wrote the Password Rules Said in 2017 That He Regretted Them. His Own Guideline Had Predicted in 2004 That Everyone Would Capitalize the First Letter and Put the Symbol at the End.
In June 2004 the National Institute of Standards and Technology published Special Publication 800-63, the Electronic Authentication Guideline, by William Burr, Donna Dodson and Timothy Polk. It was written for US federal agencies. Its Appendix A set out a method for estimating how strong a password was, and it awarded a bonus of six bits of entropy to any system that required users to include both upper case and non-alphabetic characters.
The method had no password data behind it. The authors said so. They started from Claude Shannon's estimates of the entropy of ordinary English text, noted that it would be better to have a large body of real passwords to work from but that "we have no such resource", and warned readers not to treat the rules "as anything more than a very rough rule of thumb". Login pages, email systems and online banking adopted them anyway, and not as a rough rule of thumb.
The Paragraph in the Middle
Between the caveat and the bonus, the same appendix described what would happen. It assumed that rules forcing capital letters or non-alphabetic characters "will generally be satisfied in the simplest and most predictable manner, often by putting a capital letter at the start (as we do in ordinary English) and punctuation or special characters at the end, or by some simple substitution, such as $ for the letter 's.'" It added that rules making passwords look highly random would be "counterproductive", because users would write them down.
The composition rule then got its six bits. The appendix admitted the benefit was "probably modest". What spread was the rule. The paragraph predicting how people would satisfy it stayed on page 48.
The Expiry Date
Forced rotation came along with it. The 2004 text did not ask for it. Its worked examples imagined passwords changed every two years, or every ten. Organisations settled on something much shorter. Microsoft's own Windows security baseline recommended 90 days, and later 60. At the University of North Carolina at Chapel Hill, the single sign-on password had to be changed every three months, on pain of suspension, and had to include a letter, a digit and a special character.
In 2010, three UNC computer scientists, Yinqian Zhang, Fabian Monrose and Michael Reiter, obtained 51,141 old password hashes from 10,374 closed accounts and studied how people replaced expired passwords. Capitalising one letter was common, as in "17candy#" becoming "17candY#". So was adding a digit, as in "dance#7" becoming "dance#78". Given one old password, their algorithm broke the next one for about 41 percent of accounts, in under three seconds each. For 17 percent, it took fewer than five online guesses. The paper's own conclusion was that it "calls into question the merit of continuing the practice of password expiration."
In October 2016 the UK's National Cyber Security Centre explained why its 2015 guidance had advised against regular expiry. When forced to change a password, "the chances are that the new password will be similar to the old one," and attackers "can often work out the new password, if they have the old one."
The Regret
In June 2017 NIST published SP 800-63B, a full rewrite. Verifiers "SHOULD NOT impose other composition rules", and "SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)." Its appendix noted that users respond to composition rules "in very predictable ways". A user who would have chosen "password" becomes "Password1". William Burr is among the twelve authors listed on it.
In August 2017 Burr, by then retired, told the Wall Street Journal: "Much of what I did I now regret." The guidance, he said, "was barking up the wrong tree." Coverage of the interview reported that his research had come mostly from a white paper written in the 1980s.
The Requirement
In May 2019 Microsoft took password expiration out of its security baseline, calling it "an ancient and obsolete mitigation of very low value." The explanation was brief: "If a password is never stolen, there's no need to expire it." In the same post, Microsoft said it was not proposing any change to its requirements for password complexity.
NIST's fourth revision, SP 800-63B-4, was published on 31 July 2025. The recommendations became requirements: verifiers "SHALL NOT impose other composition rules" and "SHALL NOT require subscribers to change passwords periodically." A password used as the only authentication factor must now be at least 15 characters long. NIST also requires new passwords to be checked against a list of known, common and compromised passwords. That is the empirical approach the 2004 authors wished they had the data for.
The guideline was right about two things: how people would satisfy its rules, and that the rules were only a very rough rule of thumb. Neither was the part anyone adopted. Twenty-one years after publication, the rules are forbidden in federal systems, and the paragraph that predicted why is still on page 48.
Filed from public reporting:
- National Institute of Standards and Technology — "Electronic Authentication Guideline, Special Publication 800-63 Version 1.0"
- National Institute of Standards and Technology — "Special Publication 800-63B: Digital Identity Guidelines, Authentication and Lifecycle Management"
- National Institute of Standards and Technology — "SP 800-63B-4: Digital Identity Guidelines: Authentication and Authenticator Management"
- The Wall Street Journal — "The Man Who Wrote Those Password Rules Has a New Tip: N3v$r M1^d!"
- Gizmodo — "The Guy Who Invented Those Annoying Password Rules Now Regrets Wasting Your Time"
- Zhang, Monrose and Reiter, University of North Carolina at Chapel Hill — "The Security of Modern Password Expiration: An Algorithmic Framework and Empirical Analysis"
- National Cyber Security Centre — "The problems with forcing regular password expiry"
- Microsoft — "Security baseline (FINAL) for Windows 10 v1903 and Windows Server v1903"