Bill Burr's 2003 Password Rules Were Wrong: He Apologized in 2017

The article traces mandatory complex password rules to Bill Burr's 2003 NIST guide based on a 1980s paper, reveals how they create predictable patterns, cites xkcd's entropy comparison, and notes Burr's 2017 regret and NIST's updated guidelines, yet many sites still enforce the outdated rules.

dbaplus Community
dbaplus Community
dbaplus Community
Bill Burr's 2003 Password Rules Were Wrong: He Apologized in 2017

Most internet users have encountered the familiar red error:

Password must contain uppercase, numbers, and special characters

. You comply, perhaps turning Zhangsan123 into Zhangsan123!, and three months later you're forced to change it again — so you swap the exclamation mark for a hash. This ritual has persisted for over a decade, widely assumed to be grounded in rigorous cryptography.

It is not. The rules originate from a single person, an eight‑page document, and an unverified 1980s whitepaper.

The 2003 NIST Guide That Became Global Standard

In 2003, Bill Burr, a mid‑level manager at the U.S. National Institute of Standards and Technology (NIST), authored Special Publication 800‑63B, Appendix A . The eight‑page document mandated three requirements:

Passwords must mix uppercase, lowercase, numbers, and special characters.

Passwords must be changed every 90 days.

New passwords must not match any of the previous three.

Burr was not a leading cryptographer. He lacked large‑scale breach data — hardly any existed in 2003 — so he leaned on a 1980s whitepaper written before the modern internet. Despite this thin evidence, the guide became the de facto global standard: banks, universities, corporations, and virtually every registration page adopted its rules.

Why the Rules Fail for Human‑Chosen Passwords

The requirements work perfectly for randomly generated strings like K7$mQ2!xR9pL; brute‑forcing such a password would take until the sun burns out. But humans do not generate random strings. Billions of people follow the same predictable pattern:

Capitalize the first letter.

Append a few digits at the end.

Add an exclamation mark (almost always).

Typical results: Password1!, Summer2024!, Zhangsan123#. Cracking tools have long incorporated these patterns into their dictionaries, turning “strong” passwords into trivial guesses.

Real‑World Evidence from Leaked Databases

When researchers analyzed massive leaks such as the LinkedIn breach (hundreds of millions of passwords), they confirmed the uniformity: uppercase first, numbers last, special character almost invariably an exclamation point. The entropy of such human‑crafted “complex” passwords is far lower than the policy assumes.

xkcd’s Entropy Comparison

In 2011, Randall Munroe (xkcd) illustrated the flaw with two examples: Tr0ub4dor&3 — meets all NIST rules, mixed case, leet substitutions, special character. Estimated entropy: 28 bits . correct horse battery staple — four random common words, no uppercase, no numbers, no special characters. Estimated entropy: 44 bits .

The passphrase is roughly 65,000 times stronger yet far easier to remember. Munroe’s caption summarized the tragedy: “Through 20 years of effort, we’ve successfully trained everyone to use passwords that are hard for humans to remember but easy for computers to guess.”

The original eight‑page NIST document that set global password policy.
The original eight‑page NIST document that set global password policy.
Comparison showing how predictable patterns reduce effective entropy.
Comparison showing how predictable patterns reduce effective entropy.
xkcd’s famous demonstration that a memorable passphrase outperforms a rule‑compliant complex password.
xkcd’s famous demonstration that a memorable passphrase outperforms a rule‑compliant complex password.

The Author’s Regret and NIST’s 2017 Revision

By 2017, Bill Burr was 72 and retired. In a Wall Street Journal interview he said: “Much of what I did, I now regret.”

That same year, NIST formally revised its guidance (SP 800‑63B). The new version:

Removed the mandatory special‑character requirement.

Eliminated the 90‑day forced rotation.

Recommended using long, memorable passphrases instead.

A rule born from a 1980s paper, written in eight pages by a non‑specialist, governed billions of logins for 14 years before its own author disowned it.

The Rules Are Still Running

Despite the apology and the updated standard, most registration forms today still display the same red line:

Password must contain uppercase, numbers, and special characters.

The rule’s creator has apologized, but the rule keeps running.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

authenticationpassword securityentropysecurity policyNISTxkcdBill Burr
dbaplus Community
Written by

dbaplus Community

Enterprise-level professional community for Database, BigData, and AIOps. Daily original articles, weekly online tech talks, monthly offline salons, and quarterly XCOPS&DAMS conferences—delivered by industry experts.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.