The NIST Official Who Enforced Special Characters in Passwords Has Apologized

The article traces the origin of the ubiquitous NIST password rule requiring uppercase letters, numbers, and special characters to an eight‑page 2003 guideline authored by Bill Burr, examines why the rule fails for human‑chosen passwords, and explains how NIST later rescinded it after the author expressed regret.

ITPUB
ITPUB
ITPUB
The NIST Official Who Enforced Special Characters in Passwords Has Apologized

You have probably seen the red warning that a password must contain uppercase letters, numbers, and special characters when you register an account.

In 2003, Bill Burr, a mid‑level manager at the U.S. National Institute of Standards and Technology (NIST), authored an eight‑page document (SP 800‑63B, Appendix A) that codified three requirements: mixed case, digits, special characters; mandatory change every 90 days; and prohibition of reuse.

Burr could not find large‑scale breach data at the time, so he relied on a 1980s whitepaper—written before the Internet existed—to justify the rules, and the brief became a global standard adopted by banks, schools, companies, and virtually every website.

The article questions whether the rule actually improves security. If you use a password manager to generate a random string like K7$mQ2!xR9pL, the rule is trivially satisfied and brute‑force attacks would take longer than the Sun’s lifetime. However, billions of users do not behave this way; they typically create passwords such as Password1!, Summer2024!, or Zhangsan123#, placing the capital letter first, the digit at the end, and an exclamation mark as the special character.

Leak analyses (e.g., the LinkedIn breach) show that human‑chosen passwords follow a remarkably consistent pattern, which cracking tools have already encoded into dictionaries, rendering the “complexity” requirement ineffective against modern attacks.

The article cites Randall Munroe’s 2011 xkcd comic that compares a complex password like Tr0ub4dor&3 (≈28 bits of entropy) with a passphrase correct horse battery staple (≈44 bits). The passphrase is orders of magnitude stronger and far easier to remember.

In 2017, a 72‑year‑old Bill Burr, now retired, told the Wall Street Journal that he regrets much of what he did. That same year NIST revised its guidance, dropping the mandatory special‑character and 90‑day change requirements and recommending long, memorable passphrases instead.

Despite the revision, many registration pages still display the old rule, and the outdated policy continues to affect billions of users.

Password strength comparison
Password strength comparison
Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

authenticationInformation Securitypassword policyNISTpassword strengthxkcd
ITPUB
Written by

ITPUB

Official ITPUB account sharing technical insights, community news, and exciting events.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.