Security · Tech Notes

NIST updates its password security recommendations

The National Institute of Standards and Technology has revised its password guidelines: length over complexity, no forced periodic resets, and no security questions.

October 1, 2024

The National Institute of Standards and Technology (NIST) recently updated its password security guidelines, addressing longstanding criticisms from IT professionals and making password management easier for users. Here is what changed and what it means for how you protect your accounts.

The most notable changes are:

  • Periodic forced password changes are no longer recommended.
  • Password length is emphasized over complexity.
  • Password hints and security questions are no longer sanctioned.
  • Truncated password authentication is explicitly denounced.

What the changes mean

Periodic forced password changes

Forcing users to update their password on a schedule, say every 90 days, was a mainstay of enterprise security for years. In practice, it produces less secure passwords, because many people just add a single character or number to the end of their previous password, making the result more predictable. NIST now recommends forcing a password change only when there is evidence that the previous password has been compromised.

Length over complexity

It has become standard for services to require some mix of lowercase, uppercase, numbers, and special characters (but not every special character) to generate a secure password. But most people make common substitutions (0 for O, @ for a) that do not increase security at all. Mathematically, longer passwords are much harder to crack than short ones, regardless of complexity.

So NIST is dropping its composition requirements and emphasizing length instead. It has moved its minimum requirement to 8 characters, set a recommended minimum of 15 characters, and encouraged services to allow passwords of up to 64 characters or more.

Password hints and security questions

Hints and knowledge-based authentication offer a lifeline for users who forget their password, asking questions like "Where did you go to high school?" or "What street did you grow up on?" But the answers to many of these questions can be gathered through social engineering, which makes them dangerously insecure. NIST now recommends eliminating these features entirely.

Truncated passwords

Some online services do not use your entire password for authentication. Even if they let you save a long password, they might check only the first 8 characters. NIST now says to stop doing this: if users secure their accounts with long passwords, the whole password should be required to verify their identity.

Best practices

The number of accounts per user keeps rising. On average, people now maintain well over 150 logins across work and personal accounts. Keeping strong, unique passwords for each of them is a critical step in keeping those accounts secure.

NIST's updated recommendations give users the freedom to use unique passphrases that are easier to remember and harder for attackers to crack through social engineering or brute force.

The recommendations also make clear that if every password is long, strong, and unique, no one can be expected to remember them all. A secure password manager is now a requirement for navigating the digital world safely. Several options fit different needs, from browser-based password management (Safari, Chrome, Firefox), to Apple's Passwords app, to feature-rich apps for teams and families like 1Password.

Work With Us

Have a project like this on the horizon?

If something here maps to what your organization is facing, let's talk it through — no pitch deck, just a senior technical perspective on your situation.