There's a New Way to Make Strong Passwords, and It's Way Easier

Advertisement
By Todd C. Frankel, Andrea Peterson, The Washington Post | Updated: 12 August 2016 16:53 IST

People tend to hate computer passwords, that often nonsensical jumble of letters, numbers and special keystrokes said to be essential for digital security. The secret codes seem impossible to remember. It's why every login page has a "Forgot password?" life preserver. The struggle even has a name: Password rage.

Now, a new standard is emerging for passwords, backed by a growing number of businesses and government agencies - to the relief of computer users everywhere. No longer must passwords be changed so often, or include an incomprehensible string of special characters. The new direction is one that champions less complexity in favor of length.

Passwords that once looked like this: "W@5hPo5t!," can now be this: "mycatlikesreadinggarfieldinthewashingtonpost."

Advertisement

Requiring longer passwords, known as passphrases, usually 16 to 64 characters long, is increasingly seen as a potential escape route from our painful push toward logins that only a cryptographer could love.

Advertisement

A series of studies from Carnegie Mellon University confirmed that passphrases are just as good at online security because hacking programs are thrown off by length nearly as easily as randomness. To a computer, poetry or simple sentences can be just as hard to crack. Even better: People are less likely to forget them.

"You're definitely seeing more of it," said Michelle Mazurek, one of the Carnegie Mellon researchers, now at the University of Maryland College Park. "For equivalent amounts of security, longer tends to be more useful for people."

Advertisement

One sign of change came this year from the federal agency overseeing government computer policy. The National Institute for Standards and Technology issued draft recommendations that called for a password overhaul - encouraging longer passwords and ending the practice of forcing new ones every 60 or 90 days.

"Passphrases are much harder to crack and break, and much easier to remember," said Paul Grassi, a NIST senior adviser.

Advertisement

It was an acknowledgment that current password practices are a pain.

Passwords today are "completely unusable," Grassi said. "Users forget, which creates all sorts of cyber-security problems, like writing it down or reusing them."

The demand for simpler passwords has grown along with the share of time spent online, where hard-to-recall codes restrict access not only to work and school email, but shopping, playing games, managing health claims and finding recipes. The average person has 19 to 25 different online passwords, polls have shown.

But the change to simpler password protocols remains slow. When Lorrie Cranor joined the Federal Trade Commission as chief technologist in January, she was stunned to learn that six of her government passwords came with automatic expirations. A couple months later, she had whittled that list down to four.

Cranor said NIST's draft rules send a signal to agencies and companies that the revamped password guidelines have the blessing of the federal government.

"One of the things we've seen when we talk to companies is they say, 'Well, this is all good,' but I can't change things until I have something I can point to," Cranor said.

Now, they can point to NIST special publication 800-63, which still needs final approval.

The government's move was applauded by privacy advocates such as Christopher Soghoian at the American Civil Liberties Union.

"The fact that NIST is clearly coming around to embracing modern, science-based policies is great," Soghoian said.

It's possible the government could be the nimbler mover on this topic.

Guillaume Ross, senior consultant at computer security firm Rapid7, said businesses are often forced to slow adoption of new password policies because of legacy computers.

"On those systems it's really hard for a security group to support long passwords," Ross said.

Still, Ross tells clients to focus on password length for beefing up security rather than any other variable.

Joe Hall, chief technologist at think tank Center for Democracy and Technology, has noticed easier password rules among the 800 different logins he uses. (He admits he's an outlier having so many accounts. But, he says, that's part of his job.) In recent years, he has seen more sites allowing 16 character if not longer passwords. Fewer are requiring regular resets.

"This is part of a big push to make things more usable for humans," Hall said.

Like many computer experts, Hall has been a fan of passphrases for years.

"I tell people to think of a sentence that is shocking and unpredictable, even nonsensical," he said.

One example: "The spherical brown fox jumped into the Russian Bundestag."

A friend of his likes to use pet peeves as his passwords, such as the malapropism "all intensive purposes."

Of course, most experts say passwords of any kind are outdated. Many have been pushing two-factor verification, where users have to prove their identity by entering a code sent to their email address or cellphone number. This standard is being more quickly adopted than passphrases.

In the meantime, experts caution against using popular song lyrics or poetry lines in passphrases. So no Beyoncé or Wallace Stevens. Hackers can download libraries of information to try common phrases. Mazurek suggested typing in your passphrase into a Google search bar and seeing if the search engine can auto-complete it - signifying that it's a common phrase.

Rich Shay, another Carnegie Mellon researcher, said the studies grew out of experiences on campus: School email passwords had to be eight characters long and include one uppercase letter, one lowercase letter, a special character and a number.

The researchers figured there had to be a better way.

Still, the studies showed that even with passphrases throwing in a little complexity - a number, a special character - could only help.

"There is no magic bullet," said Shay, now at MIT. "There is no perfect password."

And that's something everyone already knows.

© 2016 The Washington Post

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  2. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  3. Su From So OTT Release Date is Here! Know all the Details
  4. India's Indigenous Vikram Microprocessor Showcased at Semicon India 2025
  5. Redmi 15 5G, Note 14 Pro Prices Dropped During Diwali With Xiaomi Sale
  6. Cannibal Solar Storm May Trigger Aurora in the Sky Soon
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.