Technology · Level 2 · 195 words

Why Password Advice Changed

Original passage © Studio AM, written for Fluency.

Password advice has changed. Many sites once demanded a short string with a capital letter, a number, and a symbol. Current guidance puts more weight on length, uniqueness, and tools that reduce what a person must remember.

Length matters because every unpredictable character can multiply the possible strings. Symbols can enlarge that set too, but forced rules often lead people to predictable swaps, such as replacing a letter with a similar-looking number. No chart can promise one cracking time for every password. The rate depends on the password, the way a site protects it, the attacker’s equipment, and whether guesses happen online or against stolen data.

Reuse creates a different danger. If one service is breached, attackers may try the same email and password elsewhere. A unique password for each account limits that chain.

A password manager can create and store long, random passwords. Multi-factor authentication adds another check, and passkeys can avoid a shared password altogether. When a person must remember a password, a long and unusual passphrase may be easier than a short jumble. The goal is not one magic recipe. It is to make guessing difficult and one stolen secret less useful.

Comprehension questions

Choose an answer, then check your work. Nothing is saved or sent.

4 questions
1. What is the passage mainly about?

Show answer for question 1

D. How current password advice combines length, uniqueness, and safer tools
The passage explains length, attack conditions, unique passwords, managers, MFA, and passkeys.

2. Why can no chart promise one cracking time for every password?

Show answer for question 2

A. The rate depends on the password, protection, equipment, and kind of attack
The second paragraph directly lists the conditions that change a guessing rate.

3. In this passage, “unique” means

Show answer for question 3

B. used for only one account
A unique password is different for each account, so one breach does not open the others.

4. Why does password reuse make one breach more damaging?

Show answer for question 4

C. Attackers can try the same credentials on other accounts
The third paragraph explains that attackers may test the stolen email and password elsewhere.

Source: Written for Fluency. Original passage © Studio AM, written for Fluency.