Forget everything you think you know about passwords

You log into your office PC or email account and a message pops up: it’s time to change your password. Unless you use a free password manager (or even a paid password manager), you roll your eyes, change ‘c0mpanyN4me13’ to ‘c0mpanyN4me14’, are rewarded with a green tick, and go about your business.

Deep down you know it’s not good practice, but the rules enforced by many online services make it the only way to create passwords you’ll actually remember.

Many of these regulations derive from a set of recommendations published by the US National Institute of Standards and Technology (NIST) in 2003. They were intended to make users’ passwords harder to guess, but did so at the expense of user friendliness. 

Many online services only permit short passwords and restrict use of special characters

Many online services only permit short passwords and restrict use of special characters

In an interview with the Wall Street Journal, former NIST technology manager Bill Burr admitted he now regrets much of the advice the organization gave on creating strong logins.

At the time, he recommended picking combinations of characters that were as close to random as possible and changing them regularly, thereby making them harder to guess. That wasn’t totally beyond the realms of possibility 14 years ago, but now that we all rely on password-protected online services, remembering unique random logins for each one is simply impossible. 

“Well it frustrates everybody, me included," Burr told CBS News. “I have maybe 200 passwords. I can't remember all those, obviously.”

We're only human

Last month, NIST updated its guidelines for designers to make password authentication systems more user-friendly. The new recommendations include passwords that don’t expire arbitrarily, can be up to 64 characters long, and can include any printable characters, including spaces.

”It was surprising to see the news come up so quickly,” Steve Schult, senior director of product at LastPass, told TechRadar. “We hadn’t expected the kind of coverage it got, but for the LastPass team, it was very much in line with what we’ve been educating our customers to do for years.”

LastPass is a password management tool that stores users’ login details in a secure vault protected by a master password. It can generate a unique, strong password for all of your accounts and complete login forms automatically, so you don’t need to remember them.

A password manager and generator like LastPass means you don't have to remember dozens of unique logins

A password manager and generator like LastPass means you don't have to remember dozens of unique logins

“We had a blog post – I think it was from 2013 – where we recommended using a long passphrase that would be easier to remember,” said Schult. “Humans are not good at remembering 64-character alphanumeric passwords, and the new guidelines completely fit with our previous recommendations.”

LastPass doesn’t plan to make any changes to its password manager in response to the new NIST guidelines, but Schult recommends that online service providers pay particular attention to the new advice on password length.

“I use hundred-character passwords with numbers, letters and special characters, and I don’t re-use passwords because I want them to be as secure as possible,“ he said. “There are a lot of sites that don’t support that, and we would recommend that they take a look at the new guidelines.“

The more, the merrier

For even better security, the new NIST guidelines recommend using multi-factor authentication for sensitive accounts. This means providing another form of verification, such as a code from a smartphone app, in addition to a regular password. 

Android and iOS devices already support multi-factor authentication, as well as Facebook, Twitter and Google.

Schult echoes this advice. “With the proliferation of cloud services and devices since the original guidelines were written, password security will only take you so far. Two-factor authentication will stop security breaches in their tracks.”

TOPICS
Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years, and is here to help you choose the right devices for your home and do more with them. When not working she's a keen home baker, and makes a pretty mean macaron.

Read more
password manager
I'm a security expert - here are my biggest tips for creating a secure password for work and home life to stay safe online
Young woman working at a coffee shop with a laptop
Too many passwords, not enough brain space? Here’s how password managers can improve your life
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
Person using finger print authentication
Passwords out, passkeys in: The future of secure authentication
digital key
Microsoft really wants users to ditch passwords and switch to passkeys
Man screaming at computer with TechRadar data privacy week logo next to it.
I almost lost my entire online identity – until one tool made all the difference
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock