NIST Password Guidance: 15-Character Minimum & No More 90-Day Resets

NIST Password Guidance: 15-Character Minimum & No More 90-Day Resets

You can update your password practices to align with current NIST guidelines by focusing on length, avoiding mandatory changes, and using tools to manage your credentials. This updated approach moves away from the older, often frustrating, complexity rules that proved ineffective.

Understanding the Origins of NIST Password Guidance

Much of the password advice you may have followed for years originated from guidance NIST began developing in the early 2000s. This guidance aimed to create stronger, more secure passwords for federal authentication systems.

Bill Burr, then a manager at NIST, played a key role in shaping an appendix that would later influence password policies broadly.

The work on this guidance took place in 2003, leading to NIST Special Publication 80063, which was published in June 2004. This document served as a federal authentication standard. While the full publication covered broader topics, Appendix A specifically focused on assessing the difficulty of guessing user-created passwords.

A significant challenge at the time was the lack of real-world data on user password behavior. The appendix acknowledged this limitation, drawing on existing research for its estimates. This included work on text predictability and models for measuring password unpredictability, or entropy.

How Password Advice Evolved and Why It Was Flawed

The password advice that became widespread often led to users creating passwords like “Password1!” from “password” by simply adding a capital letter and a number.

This practice, while seemingly meeting complexity requirements, followed predictable patterns that attackers could easily exploit with specialized tools. The guidance itself noted these potential shortcuts, but still assigned security credit to composition rules.

Mandatory password resets, often on a 90-day cycle, further contributed to the problem. Although the original 2004 appendix did not explicitly mandate the 90-day reset, it discussed password lifetimes. Over time, this became a common policy. Users would typically make minor, predictable changes to their existing passwords, such as incrementing a number at the end.

This cycle of predictable changes meant that even if an attacker knew a user’s previous password, changing it to a slightly modified version offered minimal additional security. Research later confirmed that password reuse and modification often followed highly predictable patterns, providing attackers with a clear strategy rather than a significant hurdle.

The Shift to Modern NIST Password Standards

By 2017, Bill Burr, who had helped develop the earlier guidance, publicly expressed regret about some of the advice, acknowledging that the forced complexity provided less security than anticipated. The history is complex, as the original document did include caveats and predicted user shortcuts.

However, by 2017, researchers had access to extensive leaked password data. This allowed for a much clearer understanding of real-world password creation, reuse, and modification habits. This growing body of evidence highlighted the shortcomings of the previous rules, which had inadvertently created a predictable system for attackers.

The subsequent rewrite, NIST SP 800-63B, published in 2017 and updated to SP 800-63B-4 in 2025, shifted direction. It moved away from mandatory character-composition rules and routine expirations, focusing instead on rejecting common and compromised passwords.

The guidance also increased the minimum length requirement to 15 characters, supporting passphrases up to 64 characters, emphasizing length over arbitrary complexity.

Implementing Current NIST Password Best Practices

To align with current NIST password standards, prioritize using a password manager. This tool can generate and store strong, unique passwords for each of your accounts, eliminating the need to remember complex combinations yourself. This is a key step in strengthening your overall digital security.

Organizations should update their policies to remove mandatory password rotation requirements, unless there is evidence of a compromise. Instead, focus on screening new passwords against a blocklist of known weak or breached credentials.

If passwords are the sole authentication factor, a minimum length of 15 characters is recommended, with support for up to 64 characters, enabling the use of longer passphrases.

Many websites still enforce older, less effective composition rules. A 2023 study found that 15% of surveyed websites maintained these outdated requirements.

While capital letters and symbols do increase the number of possible passwords, forcing their inclusion into rigid rules for users often leads to predictable shortcuts, diminishing their intended security benefit. Getting all systems and policies to adopt the newer guidance is an ongoing process.

Frequently Asked Questions

What is the main change in NIST’s current password guidance?

The primary shift is from mandatory character complexity rules and frequent resets to prioritizing password length and screening against known weak or compromised passwords. NIST now recommends a minimum of 15 characters and encourages the use of passphrases.

Why was the old NIST password advice considered flawed?

The older advice, which often mandated uppercase letters, lowercase letters, numbers, and symbols, led users to create predictable password patterns. These patterns were easily exploited by attackers, and frequent mandatory resets did not significantly improve security.

How long should a password be according to current NIST guidelines?

Current NIST guidelines recommend a minimum password length of 15 characters. They also suggest supporting longer passphrases, up to 64 characters, to enhance security through increased length.

Should I still change my password every 90 days?

No, current NIST guidance states that routine password expiration is no longer recommended unless there is evidence that a password has been compromised. Frequent, mandatory changes often result in minor, predictable adjustments that do not effectively increase security.

What is a practical way to manage strong passwords?

Using a password manager is highly recommended. These tools can generate and securely store strong, unique passwords for all your accounts, making it easier to maintain good security practices without memorizing numerous complex credentials.

The post NIST Password Guidance: 15-Character Minimum & No More 90-Day Resets appeared first on trendblog.net.


Post a Comment

Previous Post Next Post