New school year, new password

Archived guidance: This 2016 article is retained as a historical teaching artifact, but its password advice is no longer current. Modern NIST guidance does not recommend routine password changes solely because a fixed period has elapsed. Current practice emphasizes long passwords, blocking commonly used or compromised passwords, password managers, and stronger authentication methods such as MFA and passkeys.

Hello, Monday (Wednesday — actually, Friday)!

As we all get ready for the new year, and then again 90 days from now, and in yet another three months, ad nauseum — the computer system will ask you to pick a new password to access the information you so desperately need right now.

Although this may seem like a burden — and by all means, maybe it is — you should take a couple of minutes to take care of the computer’s request to change your password and pick a secure code that is hard to decipher and easy for you to remember.

The remainder of the original article recommended password-management practices and linked to contemporary 2015–2016 password lists. Those links and recommendations have been retired rather than presented as current security instruction.

For current authentication guidance, consult NIST SP 800-63B-4 and the OWASP Authentication Cheat Sheet.

Last reviewed: August 9, 2026.

Written on January 20, 2016