Technology · Level 2 · 195 words
Why Password Advice Changed
Original passage © Studio AM, written for Fluency.
Password advice has changed. Many sites once demanded a short string with a capital letter, a number, and a symbol. Current guidance puts more weight on length, uniqueness, and tools that reduce what a person must remember.
Length matters because every unpredictable character can multiply the possible strings. Symbols can enlarge that set too, but forced rules often lead people to predictable swaps, such as replacing a letter with a similar-looking number. No chart can promise one cracking time for every password. The rate depends on the password, the way a site protects it, the attacker’s equipment, and whether guesses happen online or against stolen data.
Reuse creates a different danger. If one service is breached, attackers may try the same email and password elsewhere. A unique password for each account limits that chain.
A password manager can create and store long, random passwords. Multi-factor authentication adds another check, and passkeys can avoid a shared password altogether. When a person must remember a password, a long and unusual passphrase may be easier than a short jumble. The goal is not one magic recipe. It is to make guessing difficult and one stolen secret less useful.
Source: Written for Fluency. Original passage © Studio AM, written for Fluency.