Modern Password Guidance: Why Length and Blocklists Beat Complexity Rules
In a hurry? Skip straight to the numbers.
Open the Password Strength Calculator →The companion calculator rates a password from weak to strong based on entropy. It is worth knowing that the expert consensus on what actually makes a good password has shifted substantially in recent years, away from the familiar forced-complexity rules toward an approach built on length, blocklists, and dropping counterproductive requirements. Understanding this modern guidance explains why the old advice, mandatory symbols, frequent changes, backfired, and what genuinely improves password security instead. It reframes what a "strong" rating should really reward.
The Old Rules Backfired
For years, standard advice demanded a mix of uppercase, lowercase, digits, and symbols, plus regular password changes. In practice these rules made things worse, because they collided with human behavior. Forced to include a symbol and a number, people produced predictable patterns, a capital first letter, a "1" and "!" at the end, that attackers anticipate. Forced to change passwords every few months, people made minimal, guessable tweaks or wrote them down. The rules optimized for looking complex rather than being unpredictable, and the result was passwords that were both hard for humans and easy for machines.
What the Guidance Now Emphasizes
Updated guidance from security authorities reversed much of this, prioritizing what actually resists real attacks.
| Old approach | Modern approach |
|---|---|
| Mandatory character-class complexity | Emphasize length; allow long passphrases |
| Frequent forced expiration | Change only on evidence of compromise |
| Arbitrary composition rules | Block known-bad and breached passwords |
| Short maximums, blocked pasting | Allow long passwords and password managers |
The through-line is that unpredictability and length matter, while arbitrary complexity and rotation do not, and often hurt. A long passphrase of several words is both easier to remember and harder to crack than a short, symbol-laden string.
Length Beats Complexity
Because the search space grows exponentially with length, adding characters does far more for security than adding character types to a short password. A long passphrase can outclass a short complex password by orders of magnitude while being far easier for a human to handle. This is why modern guidance raises minimum lengths and explicitly welcomes passphrases, and why it stops blocking the long passwords and paste operations that password managers rely on. The old fixation on symbols was optimizing the wrong variable; length is where the real strength is.
Blocklists: Screening the Known-Bad
The most impactful modern addition is screening new passwords against blocklists of known-bad and previously breached passwords. Attackers overwhelmingly succeed by trying passwords that are common or have already leaked, so simply refusing to let users pick those passwords removes the easiest attacks at a stroke, something no complexity rule accomplishes. A password can satisfy every composition rule and still be terrible if it is a well-known leaked password; a blocklist catches exactly that. This shift, from prescribing structure to prohibiting the demonstrably weak, is one of the most effective changes in the new guidance.
Rethinking Rotation
Finally, modern guidance abandons routine periodic password changes for user passwords, changing them only when there is evidence of compromise. Forced rotation produced weak, incremental variations and offered little security benefit against the actual threats, while annoying users into worse habits. Removing it, and instead detecting and responding to real breaches, is both more secure and more usable. This is a good example of security advice maturing from intuition to evidence.
Judging Strength the Modern Way
Read the calculator's strength rating as a useful proxy that rewards length and character variety, but weigh it against current best practice: prioritize length and passphrases over forced complexity, screen against blocklists of breached passwords, allow password managers, and drop arbitrary rotation. The rating estimates strength from structure; understanding modern guidance is what tells you which structural choices actually matter and which old rules to leave behind.
Ready to Put This Into Practice?
Now that you understand how it works, plug in your own numbers and get an instant, accurate result.
Use the Password Strength Calculator Now →