logo

Good Essay on the History of Bad Password Policies

ID: c311353c-ec16-5437-9a44-6fe71ef70571

STIX ID: report--c311353c-ec16-5437-9a44-6fe71ef70571

Feed Name: Schneier on Security

Date Published: 2024-11-15

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

This post critiques the historical evolution of password policies, highlighting how early assumptions—such as the belief that complexity rules inherently produce strong passwords and the widespread hashing of passwords preventing effectiveness assessment—shaped decades of poor practice. It notes that only after large-scale password breaches were analyzed did the security community gain the empirical evidence showing users’ predictable, weak choices despite policy constraints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.