The Man Who Wrote the Password Rules Said in 2017 That He Regretted Them. His Own Guideline Had Predicted in 2004 That Everyone Would Capitalize the First Letter and Put the Symbol at the End.

Share
The Man Who Wrote the Password Rules Said in 2017 That He Regretted Them. His Own Guideline Had Predicted in 2004 That Everyone Would Capitalize the First Letter and Put the Symbol at the End.
Photo by Towfiqu barbhuiya / Unsplash

In June 2004 the National Institute of Standards and Technology published Special Publication 800-63, the Electronic Authentication Guideline, by William Burr, Donna Dodson and Timothy Polk. It was written for US federal agencies. Its Appendix A set out a method for estimating how strong a password was, and it awarded a bonus of six bits of entropy to any system that required users to include both upper case and non-alphabetic characters.

The method had no password data behind it. The authors said so. They started from Claude Shannon's estimates of the entropy of ordinary English text, noted that it would be better to have a large body of real passwords to work from but that "we have no such resource", and warned readers not to treat the rules "as anything more than a very rough rule of thumb". Login pages, email systems and online banking adopted them anyway, and not as a rough rule of thumb.

The Paragraph in the Middle

Between the caveat and the bonus, the same appendix described what would happen. It assumed that rules forcing capital letters or non-alphabetic characters "will generally be satisfied in the simplest and most predictable manner, often by putting a capital letter at the start (as we do in ordinary English) and punctuation or special characters at the end, or by some simple substitution, such as $ for the letter 's.'" It added that rules making passwords look highly random would be "counterproductive", because users would write them down.

The composition rule then got its six bits. The appendix admitted the benefit was "probably modest". What spread was the rule. The paragraph predicting how people would satisfy it stayed on page 48.

The Expiry Date

Forced rotation came along with it. The 2004 text did not ask for it. Its worked examples imagined passwords changed every two years, or every ten. Organisations settled on something much shorter. Microsoft's own Windows security baseline recommended 90 days, and later 60. At the University of North Carolina at Chapel Hill, the single sign-on password had to be changed every three months, on pain of suspension, and had to include a letter, a digit and a special character.

In 2010, three UNC computer scientists, Yinqian Zhang, Fabian Monrose and Michael Reiter, obtained 51,141 old password hashes from 10,374 closed accounts and studied how people replaced expired passwords. Capitalising one letter was common, as in "17candy#" becoming "17candY#". So was adding a digit, as in "dance#7" becoming "dance#78". Given one old password, their algorithm broke the next one for about 41 percent of accounts, in under three seconds each. For 17 percent, it took fewer than five online guesses. The paper's own conclusion was that it "calls into question the merit of continuing the practice of password expiration."

In October 2016 the UK's National Cyber Security Centre explained why its 2015 guidance had advised against regular expiry. When forced to change a password, "the chances are that the new password will be similar to the old one," and attackers "can often work out the new password, if they have the old one."

The Regret

In June 2017 NIST published SP 800-63B, a full rewrite. Verifiers "SHOULD NOT impose other composition rules", and "SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)." Its appendix noted that users respond to composition rules "in very predictable ways". A user who would have chosen "password" becomes "Password1". William Burr is among the twelve authors listed on it.

In August 2017 Burr, by then retired, told the Wall Street Journal: "Much of what I did I now regret." The guidance, he said, "was barking up the wrong tree." Coverage of the interview reported that his research had come mostly from a white paper written in the 1980s.

The Requirement

In May 2019 Microsoft took password expiration out of its security baseline, calling it "an ancient and obsolete mitigation of very low value." The explanation was brief: "If a password is never stolen, there's no need to expire it." In the same post, Microsoft said it was not proposing any change to its requirements for password complexity.

NIST's fourth revision, SP 800-63B-4, was published on 31 July 2025. The recommendations became requirements: verifiers "SHALL NOT impose other composition rules" and "SHALL NOT require subscribers to change passwords periodically." A password used as the only authentication factor must now be at least 15 characters long. NIST also requires new passwords to be checked against a list of known, common and compromised passwords. That is the empirical approach the 2004 authors wished they had the data for.

The guideline was right about two things: how people would satisfy its rules, and that the rules were only a very rough rule of thumb. Neither was the part anyone adopted. Twenty-one years after publication, the rules are forbidden in federal systems, and the paragraph that predicted why is still on page 48.


Filed from public reporting:

Read more

Milwaukee County Required Augmented-Reality Game Publishers to Apply for Park Event Permits After Pokémon Go Crowds Overran Lake Park. The Law Was Undone by a Cowboy-Themed Poker App and Cost $83,000 in Legal Fees.

Milwaukee County Required Augmented-Reality Game Publishers to Apply for Park Event Permits After Pokémon Go Crowds Overran Lake Park. The Law Was Undone by a Cowboy-Themed Poker App and Cost $83,000 in Legal Fees.

In July 2016, Pokémon Go was released, and Lake Park, a public park on Milwaukee's East Side, turned out to be full of places the game told people to visit. Hundreds of players arrived, and sometimes thousands, at all hours. According to the Associated Press, the result was

By The Complaints Department
Panera Launched an Unlimited Self-Serve Drinks Subscription in 2022 Alongside a Lemonade With Up to 390 Milligrams of Caffeine. The Only Limit at the Fountain Was One Cup Every Two Hours.

Panera Launched an Unlimited Self-Serve Drinks Subscription in 2022 Alongside a Lemonade With Up to 390 Milligrams of Caffeine. The Only Limit at the Fountain Was One Cup Every Two Hours.

On 19 April 2022, Panera Bread launched Unlimited Sip Club, which it billed as the first nationwide unlimited subscription for self-serve beverages. For $10.99 a month, members could take one self-serve drink every two hours during café hours, refills included. The menu covered coffee, tea, fountain soda,

By The Complaints Department
Ofo Put Millions of Yellow Bicycles on China's Streets for Anyone to Ride and Took a Small Deposit to Make Sure They Came Back. At Last Count, More Than Fifteen Million Riders Were Still Waiting for the Deposit.

Ofo Put Millions of Yellow Bicycles on China's Streets for Anyone to Ride and Took a Small Deposit to Make Sure They Came Back. At Last Count, More Than Fifteen Million Riders Were Still Waiting for the Deposit.

Ofo was founded in 2014 by Dai Wei, a Peking University graduate, and began on that university's campus. The idea was simple enough to fit on a sticker. A yellow bicycle stood on the pavement, unattended. A rider paid through an app, cycled wherever they were going, and

By The Complaints Department
Washington Let Lenders Approve $793 Billion in Pandemic Payroll Loans on the Borrower's Word. A Houston Man Reported 50 Employees and $375,000 in Monthly Payroll for a Company With No Staff, and Bought a Lamborghini.

Washington Let Lenders Approve $793 Billion in Pandemic Payroll Loans on the Borrower's Word. A Houston Man Reported 50 Employees and $375,000 in Monthly Payroll for a Company With No Staff, and Bought a Lamborghini.

The Paycheck Protection Program opened in April 2020, weeks after the CARES Act created it. Its purpose was to keep small businesses paying their employees through the first lockdowns, and its governing principle was speed. The loans were fully guaranteed by the Small Business Administration, made through private lenders, and

By The Complaints Department