A decade of password rules produced a generation of passwords like Summer2024! — technically compliant with every requirement, and trivially guessable. The advice has changed, and it is worth knowing which parts survived.
Length beats complexity
Every character you add multiplies the number of combinations an attacker has to try. Adding a symbol to an eight-character password helps far less than making it sixteen characters of plain letters. This is why passphrases work: several unrelated words are both longer and easier to remember than a scrambled string.
Never reuse
This is the one that actually matters. When a site is breached, the stolen passwords are immediately tried against every other major service. A unique password per account turns a breach into an inconvenience instead of a cascade.
Stop rotating on a schedule
Forced ninety-day changes were standard for years and are now advised against by most security guidance. People respond to forced rotation predictably — the same password with an incrementing number — which is weaker than leaving a strong password alone. Change a password when there is a reason to.
“Change your password because something happened, not because a calendar said so.”
Use a manager
Unique long passwords everywhere is impossible to sustain by memory, and that is the point. A password manager makes the correct behaviour the easy one. Add two-factor authentication on anything that offers it and the remaining risk drops sharply again.
TRY THE TOOLPassword GenGenerate strong, secure passwords.