We're sorry but this app doesn't work properly without JavaScript enabled. Please enable it to continue.

This lesson's interactive features are locked, please to keep using them

Authentication Misconceptions

Many password rules you've encountered in the wild are, unfortunately, just security theater. They add friction without stopping how attackers guess and reuse passwords. For example, "change your password every 90 days" may sound secure, but users usually just make predictable changes:

  • OtterRiver1!
  • OtterRiver2!
  • OtterRiver3!

Current NIST password guidance says not to require periodic password changes. Only force a change when there's evidence the password has been compromised!

Complexity Requirements Are Harmful

The silly game of "Your password must include uppercase and lowercase letters, numbers, and symbols" leads to passwords like Password1!.

Humans are predictable, and given simple rules, we follow patterns:

  • Capital letter at the start
  • Number and symbol at the end
  • Common substitutions (@ for a, 3 for e)

Attackers know this! Password crackers are built around these patterns. It's way better to prioritize length, block known-compromised passwords, and support password managers. A randomly generated passphrase can be easier to remember while still being hard to guess.

-- The incredible XKCD

Weak Security Questions

"What was your first pet's name?" is not effective authentication. These kinds of questions are:

  • Easy to guess
  • Discoverable on social media
  • Answers rarely change

They're just recovery vulnerabilities disguised as security features.