Why the password rules meant to protect you make you less safe
Password rules requiring capitals, numbers and symbols forced people to reuse passwords instead, making them weaker.
For decades, we were told a strong password needs uppercase and lowercase letters, numbers, and special characters. The rules seemed logical, but the person who helped create them regretted the advice.
William "Bill" Burr, a manager at the US National Institute of Standards and Technology (NIST), wrote the guidance in 2004. In 2017, he told reporters: "It just drives people bananas."
Research showed the rules backfired. Instead of making passwords stronger, they pushed people to reuse passwords or make predictable changes.
A 2021 study found that stricter complexity rules did not necessarily create better passwords and could frustrate users. When passwords are reused across services, one breach exposes everything.
NIST updated its guidance in 2017 to recommend checking passwords against known breaches instead of relying solely on character rules. Yet most websites still enforce the old approach.
- 2004
- Guidance published
- 2017
- Burr's regret stated
- 2021
- Study on rule effectiveness
- NIST
- Organization
Why it mattersIf you follow complex password rules but reuse the same password across sites, you're less secure than using one strong, unique phrase.
AustraliaAustralian banks, services and workplaces often enforce outdated password rules, putting users at greater risk of reuse and breach exposure.
✓ Claims checked against the source and corrected before publish. checked 1 h ago
Open this story in InSnip →





