THE ID10T FILES · TICKET #0006 · 4 MIN READ (BILLABLE)
Password1! Is Not a Password. It's a Confession.
Adding an exclamation point doesn't make your password secure. It just makes it excited.
CompromisedDave works at an office that makes everyone change their password every 90 days. Dave has a system.
Password1! became Password2!, which became Password3!. Dave is currently on Password27! and he is very proud that he has never once forgotten it.
Neither has anyone else. It's on a sticky note under his keyboard. "Hidden."
Where we find the sticky notes
- Under the keyboard. Always first. It's the "under the doormat" of passwords.
- On the edge of the monitor, facing out, like a name tag.
- Taped to the inside of the desk drawer.
- In a Word document named Passwords, on the desktop, next to a folder named Taxes.
- In the phone, saved as a contact named "Password Guy."
Then there's the shared login. Username: admin. Password: Admin123. Used by six current employees and one former employee who left in 2021 and, as far as we can tell, still logs in on Fridays.
About that exclamation point
Somebody once told Dave that a password needs a capital letter, a number, and a symbol. So Dave built Password1!, which technically has all three. So did millions of other people. Which is why it's on every list of leaked passwords, and why password-cracking tools try it in the first few seconds.
The exclamation point doesn't make it secure. It just makes it excited.
The twist nobody asked for
We hate to defend Dave, but the rules that created Dave are outdated. NIST's current password guidance says length beats complexity rules, that forcing everyone to change passwords on a schedule mostly produces things like Password27!, and that systems should block passwords already known from breaches. So Dave's company made Dave worse.
We still blame Dave. Out of habit.
The annoyingly correct part
Use a password manager and let it create long, unique passwords for every account. For the few you have to type, use a long passphrase of four or more random words. Turn on MFA everywhere, especially email. And never reuse your work password anywhere else. That's how one breach turns into two.
Names changed to protect the ID10Ts. Also, this story is fiction. Any resemblance to your office is your office's fault.