The Ordinary Review

Careful reporting on everyday money

Innovation

Five Things Worth Checking in a Password, and the Rules That Quietly Stopped Applying

Length, reuse, recovery paths and second factors matter more than the composition rules most of us were trained on, and each one takes a different amount of upkeep.

Lucinda Fairbairn|

A kitchen table with an open notebook listing account names, a smartphone showing an authenticator app screen, a small key-shaped security token, and a mug b...
A kitchen table with an open notebook listing account names, a smartphone showing an authenticator app screen, a small key-shaped security token, and a mug b...

The password advice most of us absorbed came from workplaces, and it was mostly about composition: a capital letter, a digit, a symbol, and a fresh version every quarter. That guidance has been substantially revised, and the National Institute of Standards and Technology is the body responsible for the federal digital identity guidelines that shaped it in the first place. What replaced it asks less of you on any given Tuesday and more of you once or twice a year. The useful skill is not memorizing a new rulebook. It is knowing which five things actually change your exposure, and which ones you can stop thinking about.

Length, which now carries the weight that symbols used to

A twelve-character password built from three unrelated words resists guessing better than an eight-character one stuffed with punctuation, and it is far easier to type on a phone keyboard at a bus stop. That is the trade the revised guidance recognizes: complexity rules pushed people toward predictable substitutions, the exclamation point at the end and the zero standing in for an O, which attackers model cheaply. Length is the one dimension that gets expensive to attack fast. In week-to-week terms, this means you can stop auditing your passwords for character variety, a task that never protected much, and check instead that the handful you type by hand are genuinely long.

Reuse, because it is the only failure that spreads

A weak password on a single account costs you that account. A reused password costs you every account that shares it, and the spread happens without anyone targeting you: credentials leaked from a forum breach get replayed against email providers and banks in bulk. This is the check with the highest return, and it is also the one that reveals how many logins you actually have. Most households discover somewhere between forty and a couple hundred. You do not need to fix them all. Fix the email account first, because it is the recovery route for everything else, then the bank, then anything holding a stored card.

Whether the account has a second factor, and which kind

Two accounts can both be described as having two-factor authentication and be meaningfully different in what they resist. A code from an authenticator app or a hardware key is bound to something you hold; a code sent by text can be redirected by someone who persuades a carrier to move your number. For a household email account or anything financial, the upgrade from text codes to an app is a ten-minute job you will do once and never revisit. For a loyalty account, text codes are fine and arguing about it wastes an evening. Judgement here is mostly about deciding which accounts deserve the extra friction.

Whether the recovery path still belongs to you

This is the check almost nobody runs, and it is the one that quietly rots. Accounts you opened years ago may still list a work email you no longer have, a phone number from two carriers back, or security questions answered with facts that are now on a public genealogy site. When you eventually lose a device or forget a password, the recovery path is the whole game, and a stale one turns a five-minute reset into a support ticket with identity documents attached. Once a year, on the same afternoon you handle some other piece of annual paperwork, open the security page of your three most important accounts and read what is listed there.

Where the answers live when you are not at your own desk

Every one of the checks above assumes you can find the password when you need it, and that assumption breaks at airports, in urgent care waiting rooms, and on the phone with a utility company. So the fifth check is about storage rather than the password itself: whether your system survives a lost phone, a dead laptop, and a household member who needs access while you are unreachable. A manager with printed recovery codes in a fireproof box handles all three. A browser vault tied to one signed-in device handles the first two poorly. Whatever you choose, the test is the same: could someone else in the house get in with your written instructions and nothing else?

What the upkeep actually looks like across a year

The rules that were withdrawn were the ones that demanded constant attention, and the rules that replaced them ask for concentrated attention rarely. Forced rotation is gone as a blanket practice, which means you change a password when there is a reason: a breach notice, a shared login someone has left, a nagging sense that you typed it into something that looked wrong. That converts password hygiene from a recurring chore into an event-driven one. Week to week, the work is almost nothing beyond letting a manager fill fields. Once or twice a year, you sit down for an hour and check recovery details, second factors, and the small pile of reused credentials you already know about.

Judgement, in this area, is mostly the ability to sort accounts by what losing one would actually cost, and to spend your attention accordingly. The email address that resets everything else, the bank, the brokerage, the tax software holding prior-year returns: those earn long unique passwords, app-based second factors, and current recovery paths. The pizza ordering site earns whatever the manager generated and no further thought. Getting that sorting right is worth more than any individual password decision, and it is the part that keeps paying off as the specific advice continues to shift.

More from the desk