The Ordinary Review

Careful reporting on everyday money

Innovation

Password Advice Changes Every Year. Four Tests That Tell You Which Changes Matter

Guidance on passwords keeps shifting, so the useful skill is not memorizing rules but judging which new advice earns a place in your ordinary week.

Lucinda Fairbairn|

A kitchen table with an open laptop showing a login screen, a small hardware security key on a keyring beside it, a printed sheet of backup recovery codes, a...
A kitchen table with an open laptop showing a login screen, a small hardware security key on a keyring beside it, a printed sheet of backup recovery codes, a...

The advice you were given about passwords in 2012 was confident, specific, and largely wrong, and the advice being given now is confident and specific in a different direction. That pattern will repeat. What survives the churn is not a rule set but a way of weighing any new instruction against what it actually asks of you on a Tuesday morning when you are locked out of a payroll portal and have eleven minutes before a call. Building that judgement is cheaper than relearning rules every three years, and it holds up when the next round of guidance arrives.

Sort your accounts before you sort your passwords

Most people carry somewhere between eighty and three hundred credentials, and treating them as one undifferentiated pile is why password hygiene collapses. There are perhaps six accounts where a compromise reshapes your month: the primary email, the phone carrier account, the bank, the brokerage or retirement login, the password manager itself, and whatever holds your tax records. Everything else, the pizza chain, the utility portal, the forum you post on twice a year, sits in a second tier where a breach is an inconvenience. Sorting first tells you where to spend attention, and it converts a vague obligation into about six concrete jobs.

The reason the top tier is short is that those accounts are recovery paths for the others. Control of your email is control of nearly every reset link you will ever receive, and control of your phone number is control of a great many second factors. That makes email and carrier accounts structurally more valuable than the bank they protect, which is the opposite of how most households rank them. Anyone weighing where to add a hardware key or a longer passphrase should start with the account that unlocks the rest rather than the one holding the money.

Judge advice against what actually happens, not what sounds dangerous

Almost nobody is sitting at a terminal guessing your password character by character. The ordinary compromise arrives from a list: a company you used years ago was breached, the credentials leaked, and software tries that same email and password combination against several hundred other services at machine speed. That is credential stuffing, and it is indifferent to whether your password contains an exclamation point. Reuse is the vulnerability. Complexity theater, the substitution of a three for an E, was designed against a threat that matters far less than the one you actually face.

Hold any new recommendation against that picture and most of it sorts itself. Advice that reduces reuse or blunts phishing is worth the friction; advice that only makes an individual password harder for a human to guess is mostly noise. The National Institute of Standards and Technology is the body responsible for federal digital identity guidance, and its shift over the past decade has moved in exactly this direction, away from composition rules and toward length, screening against known-breached passwords, and not forcing changes without cause. When guidance changes again, the test is whether it addresses list-based attacks or theater.

Four tests to run on any new instruction

The first test is whether it eliminates reuse somewhere it still exists, because that is the single change with the largest return and the one most people have only half-finished. The second is whether it survives a bad day: a lost phone, a dead laptop, a hospital stay. A scheme that is secure only while you are healthy and holding your primary device is not a scheme, it is a gamble. The third is what it costs you weekly in seconds and irritation, because anything expensive gets abandoned by March. The fourth is whether it protects the recovery path or only the front door.

Applied honestly, those four tests do a lot of sorting. A password manager passes all four, which is why the advice has consolidated around it. Text message codes pass the third easily and the second and fourth poorly, which is why they are now treated as better than nothing rather than as the standard. A hardware security key on your email account passes the fourth decisively and the second only if you bought two and stored the spare somewhere other than the same drawer. Buying the second key is the entire difference between a good setup and a fragile one.

The week-to-week reality, which is where schemes actually fail

In a normal week you will log into perhaps fifteen services, half of them from a browser that already remembers you, and you will hit two or three genuine friction points: a new device, an expired session, a service that has quietly changed its login flow. Those moments are when people paste a password into the wrong window, approve a push notification they did not initiate, or type credentials into a page reached from an email. Judgement here is mostly a single habit, which is refusing to authenticate from a link and instead opening the site yourself. It costs about eight seconds.

The other weekly reality is maintenance you never scheduled. Recovery codes printed in 2021 and stored in a folder you have since moved. A second factor tied to a phone number you gave up. A shared streaming login your adult child changed without telling anyone. None of this is urgent in any given week, which is precisely why it accumulates, and the fix is an hour twice a year rather than vigilance. Open the top six accounts, confirm the recovery email and phone are current, regenerate backup codes, and write down where the spare key lives.

Passkeys, and holding two systems at once for a while

The direction of travel is toward passkeys, credentials bound to your device and unlocked by a fingerprint or a PIN, with nothing typed and nothing to phish. Where a site offers one and it syncs through a manager you already trust, taking it is usually a straightforward improvement. What matters for the next several years is that you will be running both systems simultaneously, passkeys on the services that support them and passwords everywhere else, and the password side still needs to be clean. A partial migration that leaves reused passwords behind on forty sites has not moved you very far.

Treat the transition the way you would treat replacing windows one wall at a time. The new units go in where they do the most good, the old ones stay serviceable until their turn comes, and you keep a clear record of what has been done. The top-tier accounts get passkeys first, because that is where phishing resistance pays. The long tail can wait for the sites themselves to catch up, which they will, at varying speeds and without telling you.

Nobody is going to send you a notice when the guidance shifts again. What you can do is keep a scheme whose weak points you already know, check it on a schedule you chose rather than one an attacker chose for you, and treat each new recommendation as something to be tested rather than obeyed.

More from the desk