The NIST Official Who Enforced Special Characters in Passwords Has Apologized
The article traces the origin of the ubiquitous NIST password rule requiring uppercase letters, numbers, and special characters to an eight‑page 2003 guideline authored by Bill Burr, examines why the rule fails for human‑chosen passwords, and explains how NIST later rescinded it after the author expressed regret.
You have probably seen the red warning that a password must contain uppercase letters, numbers, and special characters when you register an account.
In 2003, Bill Burr, a mid‑level manager at the U.S. National Institute of Standards and Technology (NIST), authored an eight‑page document (SP 800‑63B, Appendix A) that codified three requirements: mixed case, digits, special characters; mandatory change every 90 days; and prohibition of reuse.
Burr could not find large‑scale breach data at the time, so he relied on a 1980s whitepaper—written before the Internet existed—to justify the rules, and the brief became a global standard adopted by banks, schools, companies, and virtually every website.
The article questions whether the rule actually improves security. If you use a password manager to generate a random string like K7$mQ2!xR9pL, the rule is trivially satisfied and brute‑force attacks would take longer than the Sun’s lifetime. However, billions of users do not behave this way; they typically create passwords such as Password1!, Summer2024!, or Zhangsan123#, placing the capital letter first, the digit at the end, and an exclamation mark as the special character.
Leak analyses (e.g., the LinkedIn breach) show that human‑chosen passwords follow a remarkably consistent pattern, which cracking tools have already encoded into dictionaries, rendering the “complexity” requirement ineffective against modern attacks.
The article cites Randall Munroe’s 2011 xkcd comic that compares a complex password like Tr0ub4dor&3 (≈28 bits of entropy) with a passphrase correct horse battery staple (≈44 bits). The passphrase is orders of magnitude stronger and far easier to remember.
In 2017, a 72‑year‑old Bill Burr, now retired, told the Wall Street Journal that he regrets much of what he did. That same year NIST revised its guidance, dropping the mandatory special‑character and 90‑day change requirements and recommending long, memorable passphrases instead.
Despite the revision, many registration pages still display the old rule, and the outdated policy continues to affect billions of users.
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
ITPUB
Official ITPUB account sharing technical insights, community news, and exciting events.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
