
Everything You Were Told About Passwords Is Out of Date
Take a look at this password:
@LD)"-fQU&6Lz!g6k/Uf
It looks impenetrable. It has upper case, lower case, numbers, symbols, and absolutely no discernible pattern. It is the sort of thing a security policy dreams about. It is also the sort of thing no human being will ever remember, which means it will end up on a sticky note under a keyboard, in a Notes app, or in a spreadsheet called passwords.xlsx.
Here is the uncomfortable part: that password is strong despite the symbols, not because of them. What is doing the heavy lifting is the fact that it is twenty characters long. And the way most organisations still handle passwords (force complexity, force a change every 90 days, hope for the best) is actively making them less secure, not more.
The 90-Day Rotation Myth
Mandatory password expiry made sense in a world that no longer exists. It was designed for an era when a stolen password hash might take months of offline grinding to crack. Rotating every 90 days meant that by the time an attacker got in, the door had already been re-keyed.
That threat model is dead. Modern attacks are not slow. Credentials are stolen through phishing pages, infostealer malware and breach dumps, then used within hours, sometimes minutes. A 90-day window is not a defence against that. It is a formality.
Worse, forced rotation has a predictable side effect: it changes human behaviour, and never for the better. Ask someone to invent a brand new, complex, unrelated password four times a year and they will not do it. They will do what everyone does:
- Increment it.
Summer2024!becomesSummer2025!becomesSummer2026!. - Shuffle a character. Move the exclamation mark, swap an
ofor a0, capitalise a different letter. - Write it down. Because they have now had eleven versions of the same password in three years and cannot keep track.
- Reuse it everywhere. One password they can just about remember, applied to every system they touch.
Attackers know this. Password-cracking tools have built-in rules specifically for it: take a known password from a previous breach, then try the obvious mutations. If your old password leaked, your new one is often a handful of guesses away. Rotation does not close the gap; it hands the attacker a template.
The UK's National Cyber Security Centre has advised against routine password expiry for the best part of a decade. NIST removed mandatory periodic rotation from its digital identity guidelines in 2017. Microsoft dropped password expiry from its Windows security baselines in 2019. The guidance changed years ago. Most policies simply never caught up.
The modern consensus is simple: change a password when there is a reason to. If it appears in a breach, if a device is compromised, if someone with access leaves, if there is any hint of suspicious activity, change it immediately. Otherwise, a strong, unique password that nobody else knows does not become weaker because a calendar rolled over.
Length Beats Complexity. It Isn't Close.
The strength of a password comes down to one thing: how many possible combinations an attacker would have to work through. Adding symbols widens the pool of characters available at each position. Adding length multiplies the whole thing again, for every single character you add.
Those two are not equivalent. Widening the character set gives you a modest, one-off gain. Extra length compounds, and it compounds fast.
Compare two passwords. The first is twelve characters using the full keyboard: upper, lower, numbers, symbols, the works. The second is twenty characters of nothing but lower-case letters.
| Password | Character set | Length | Roughly equivalent to |
|---|---|---|---|
Tr0ub4dor&3X | 94 characters | 12 | ~79 bits of strength |
correcthorsebatterystaple | 26 characters | 20 | ~94 bits of strength |
Every extra bit doubles the work for an attacker. That fifteen-bit gap means the plain lower-case passphrase is roughly thirty thousand times harder to crack than the symbol-laden one, with no symbols, no numbers, and nothing to forget.
To put some rough numbers on it: assume an attacker who has stolen a password database and can make a trillion guesses per second offline. The twelve-character complex password falls in a few thousand years. The twenty-character lower-case one takes hundreds of millions. Both are fine on paper, but only one of them is still standing when hardware gets ten thousand times faster, and only one of them is memorable.
This is the fundamental point that complexity rules get wrong. P@ssw0rd1! satisfies almost every corporate password policy ever written. It is also in every cracking dictionary on earth, and it falls instantly. Meanwhile rusty kettle moth garden breaks nearly all of those rules and is vastly stronger.
A quick caveat on randomness
Length only helps if the content is genuinely unpredictable. A twenty-five character quote from a well-known film is long and useless, because attackers feed song lyrics, film scripts and book passages straight into their wordlists. The trick is length plus unpredictability: four or five genuinely random, unrelated words, chosen at random rather than by you. Human-chosen "random" words are far more predictable than we like to think.
So Where Does That Leave Symbol Soup?
Here is the nuance that gets lost. There is nothing wrong with @LD)"-fQU&6Lz!g6k/Uf. It is an excellent password. The problem was never the symbols. It was the expectation that a person would memorise it and type it by hand.
Remove that expectation and the calculation changes completely. If a password is generated, stored and filled in automatically, it can be as long and as unreadable as you like, because no human ever has to look at it.
Which gives you two different jobs, and two different answers:
- Passwords you have to remember (and there should only ever be one or two of these) want to be long, memorable passphrases. Four or five random words. Easy to type, easy to recall, brutally hard to guess.
- Every other password should be sixteen-plus characters generated at complete random, unique to that one account, and you should never be expected to remember it, but if you need to manually type it, it should still be easy enough to type.
That second category is the one that actually protects you. The single biggest real-world risk today is not that someone brute-forces your password. It is credential stuffing. A website you signed up to a decade ago gets breached. Your email address and password end up in a dump traded online. Attackers take that pair and fire it at Microsoft 365, your banking, your accounting software, your cloud storage. If you reused that password anywhere, they are in, and no amount of complexity in the world helps, because they are not guessing. They already have it.
Unique passwords everywhere means one breach stays one breach. It is the single highest-impact change most businesses can make. And it is completely impossible to do by memory, which is exactly why password managers exist.
The Modern Password Checklist
- Stop forcing routine expiry. Change passwords on evidence of compromise, on staff departure, or on suspicion, not on a timer.
- Prioritise length. Set a minimum of at least fourteen characters and encourage far longer. Drop the arbitrary "must contain a symbol" rules that only ever produce
Password1!. - Make every password unique. No exceptions, no "but it's only a low-risk account".
- Turn on multi-factor authentication everywhere. Preferably an authenticator app or dedicated password manager, never use email or SMS.
- Screen against known breaches. A password that has already leaked is worthless no matter how long it is.
- Use a password manager. Every item above becomes effortless with one; and nearly impossible without one.
One Password. That's It.
This is where Keeper comes in. You create one strong master password (a long passphrase you can actually remember), and that is genuinely the last password you will ever need to memorise.
Everything else is generated for you, stored encrypted, and filled in automatically. Twenty-plus characters of random worded passwords for every single account, and you never have to see any of it.
Autofill does the work across your browser and apps, so logging in is faster than typing a weak password ever was. Your vault syncs securely across all your devices, whether desktop, laptop, phone or tablet, so the credentials you save at your desk are already there on your mobile.
And a family plan, included free
Security does not stop at the office door. Home accounts get reused at work, and work accounts get accessed from home, so protecting one without the other leaves an obvious gap.
That is why every user on our plans also gets a Keeper Family plan included at no extra cost, covering up to five people in their household. Partners, children, parents, pets: everyone gets the same protection, at no additional charge, for as long as that person is part of the business.
And if someone does move on? They are not locked out of their own digital life. They can simply choose to continue the family plan themselves, paying directly to Keeper, with no interruption and nothing lost. Their passwords stay exactly where they are.
Ready to stop remembering passwords?
Ditch the compliance breaking spreadsheet, retire the sticky notes that long for wandering eyes, and forget the 90-day reset email for good. One master password is all you need!