NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

The new way to make strong passwords, (it's way easier)

By Todd C. Frankel
Washington Post·
11 Aug, 2016 10:45 PM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Those Beyonce lyrics won't work as a passphrase - they're too easy for hackers to guess. Photo / AP

Those Beyonce lyrics won't work as a passphrase - they're too easy for hackers to guess. Photo / AP

People tend to hate computer passwords, that often nonsensical jumble of letters, numbers and special keystrokes said to be essential for digital security. The secret codes seem impossible to remember. It's why every login page has a "Forgot password?" life preserver. The struggle even has a name: Password rage.

Now, a new standard is emerging for passwords, backed by a growing number of businesses and government agencies - to the relief of computer users everywhere. No longer must passwords be changed so often, or include an incomprehensible string of special characters. The new direction is one that champions less complexity in favour of length.

Passwords that once looked like this: "W@5hPo5t!," can now be this: "mycatlikesreadinggarfieldinthewashingtonpost."

Requiring longer passwords, known as passphrases, usually 16 to 64 characters long, is increasingly seen as a potential escape route from our painful push toward logins that only a cryptographer could love.

A series of studies from Carnegie Mellon University confirmed that passphrases are just as good at online security because hacking programs are thrown off by length nearly as easily as randomness. To a computer, poetry or simple sentences can be just as hard to crack. Even better: People are less likely to forget them.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

"You're definitely seeing more of it," said Michelle Mazurek, one of the Carnegie Mellon researchers, now at the University of Maryland College Park. "For equivalent amounts of security, longer tends to be more useful for people."

One sign of change came this year from the federal agency overseeing government computer policy. The National Institute for Standards and Technology issued draft recommendations that called for a password overhaul - encouraging longer passwords and ending the practise of forcing new ones every 60 or 90 days.

"Passphrases are much harder to crack and break, and much easier to remember," said Paul Grassi, a NIST senior adviser.

Advertisement
Advertise with NZME.

It was an acknowledgement that current password practises are a pain.

Passphrases are much harder to crack and break, and much easier to remember.

Paul Grassi, NIST senior adviser

Passwords today are "completely unusable," Grassi said. "Users forget, which creates all sorts of cybersecurity problems, like writing it down or reusing them."

The demand for simpler passwords has grown along with the share of time spent online, where hard-to-recall codes restrict access not only to work and school email, but shopping, playing games, managing health claims and finding recipes. The average person has 19 to 25 different online passwords, polls have shown.

But the change to simpler password protocols remains slow. When Lorrie Cranor joined the Federal Trade Commission as chief technologist in January, she was stunned to learn that six of her government passwords came with automatic expirations. A couple months later, she had whittled that list down to four.

Discover more

Opinion

Comment: Catch 'em all, but be careful

11 Jul 06:45 PM
Opinion

Be ready when Cozy Bear comes

26 Jul 08:00 PM
Opinion

Juha Saarinen: Watch out, or your Skype credit could be someone else's

29 Jul 12:30 AM
New Zealand

Missing man's Facebook shows activity

04 Aug 07:20 AM

Cranor said NIST's draft rules send a signal to agencies and companies that the revamped password guidelines have the blessing of the federal government.

Passwords today are completely unusable - Users forget, which creates all sorts of cybersecurity problems, like writing it down or reusing them.

Paul Grassi

"One of the things we've seen when we talk to companies is they say, 'Well, this is all good,' but I can't change things until I have something I can point to," Cranor said.
Now, they can point to NIST special publication 800-63, which still needs final approval.
The government's move was applauded by privacy advocates such as Christopher Soghoian at the American Civil Liberties Union.

"The fact that NIST is clearly coming around to embracing modern, science-based policies is great," Soghoian said.

On those systems it's really hard for a security group to support long passwords.

Guillaume Ross, senior consultant at computer security firm Rapid7

It's possible the government could be the nimbler mover on this topic.
Guillaume Ross, senior consultant at computer security firm Rapid7, said businesses are often forced to slow adoption of new password policies because of legacy computers.

"On those systems it's really hard for a security group to support long passwords," Ross said.

Still, Ross tells clients to focus on password length for beefing up security rather than any other variable.

Advertisement
Advertise with NZME.

Joe Hall, chief technologist at think tank Center for Democracy and Technology, has noticed easier password rules among the 800 different logins he uses. (He admits he's an outlier having so many accounts. But, he says, that's part of his job.) In recent years, he has seen more sites allowing 16 character if not longer passwords. Fewer are requiring regular resets.

"This is part of a big push to make things more usable for humans," Hall said.
Like many computer experts, Hall has been a fan of passphrases for years.

most experts say passwords of any kind are outdated. Many have been pushing two-factor verification, where users have to prove their identity by entering a code sent to their email address or cellphone number.
most experts say passwords of any kind are outdated. Many have been pushing two-factor verification, where users have to prove their identity by entering a code sent to their email address or cellphone number.

"I tell people to think of a sentence that is shocking and unpredictable, even nonsensical," he said.

One example: "The spherical brown fox jumped into the Russian Bundestag."

A friend of his likes to use pet peeves as his passwords, such as the malapropism "all intensive purposes."

Of course, most experts say passwords of any kind are outdated. Many have been pushing two-factor verification, where users have to prove their identity by entering a code sent to their email address or cellphone number. This standard is being more quickly adopted than passphrases.

Advertisement
Advertise with NZME.

In the meantime, experts caution against using popular song lyrics or poetry lines in passphrases. So no Beyoncé or Wallace Stevens. Hackers can download libraries of information to try common phrases. Mazurek suggested typing in your passphrase into a Google search bar and seeing if the search engine can auto-complete it - signifying that it's a common phrase.

Rich Shay, another Carnegie Mellon researcher, said the studies grew out of experiences on campus: School email passwords had to be eight characters long and include one uppercase letter, one lowercase letter, a special character and a number.

The researchers figured there had to be a better way.

Still, the studies showed that even with passphrases throwing in a little complexity - a number, a special character - could only help.

"There is no magic bullet," said Shay, now at MIT. "There is no perfect password."
And that's something everyone already knows.

Save

    Share this article

Latest from Business

New Zealand

'Prime focus': Avocado industry targets global markets

09 May 03:08 AM
Premium
Property

Nine fires in five years: Environment Court rules on scrap metal dealer

09 May 03:00 AM
Premium
Tourism

Uber adds new ride option for Kiwis in Asia-Pacific first

09 May 02:00 AM

“Not an invisible footprint”: Why technology supply chains need optimising

sponsored
Advertisement
Advertise with NZME.

Latest from Business

'Prime focus': Avocado industry targets global markets

'Prime focus': Avocado industry targets global markets

09 May 03:08 AM

NZ Avocado plans to diversify export markets, focusing on North America and Asia.

Premium
Nine fires in five years: Environment Court rules on scrap metal dealer

Nine fires in five years: Environment Court rules on scrap metal dealer

09 May 03:00 AM
Premium
Uber adds new ride option for Kiwis in Asia-Pacific first

Uber adds new ride option for Kiwis in Asia-Pacific first

09 May 02:00 AM
Premium
NZME's bitter board battle over: Joyce and Grenon to join in peace deal

NZME's bitter board battle over: Joyce and Grenon to join in peace deal

09 May 01:59 AM
Deposit scheme reduces risk, boosts trust – General Finance
sponsored

Deposit scheme reduces risk, boosts trust – General Finance

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP