“Minimum eight characters, at least one uppercase letter, a number, a special symbol, and no spaces”. This is an example of the classic restrictions that many sites impose when creating passwords, and its origin is the document “NIST Special Publication 800-63 Appendix A.”, written by Bill Burr in 2003. Fourteen years later, computer security has changed a lot, and Burr acknowledges in a way that his rules only managed to complicate users’ lives, so he decided to apologize publicly.

Bill Burr: The Creator of the Famous Password Rules Apologizes
Passwords

Our recommendation to use password managers remains intact. Their built-in generators can create much more complex combinations than we can imagine, and the best part is that we don’t need to remember them. However, the real problem for security officers is that group of users who, in addition to not adopting a manager, also use very weak passwords. In 2003, the US NIST published a document known as “NIST Special Publication 800-63. Appendix A.”, which was subjected to several modifications, but whose original version was in charge of an administrator at the institute named Bill Burr.

Bill Burr: The Creator of the Famous Password Rules Apologizes
These limits are counterproductive: the user complies with them with minimal effort, and the result is an insecure password.

Burr’s text defines the requirements for creating a secure password, which basically impose the use of uppercase letters, symbols, and numbers, along with their replacement every 90 days. These requirements were adopted by millions of services and portals on the Web, and to be honest, they haven’t disappeared. His intentions were good, but fourteen years later Burr came to the conclusion that he delivered incorrect information. Users found serious difficulties remembering and writing passwords, leading to the use of very short and insecure strings, and whose “renewal” every three months was the simple change of one number for another.

Why did this happen? First, Burr is not a computer security expert, and second, his information sources had been developed in the ’80s, before the Web as we know it existed. Now retired and at 72 years old, Burr decided to apologize publicly for the inconvenience caused, but we can’t blame him for everything. 2003 was a time when not so much emphasis was placed on security. The available studies were limited in number and quality, while the world used Windows XP SP1, a real sieve if ever there was one.

Source: