Featured image for Password Requirements: 28 Rules That Actually Matter

Password Requirements: 28 Rules That Actually Matter

Updated on

Join the club, become a member for free.

Get started

Most password advice is fifteen years out of date. The symbols, the forced monthly changes, the demand for a capital letter in position three. Security researchers stopped recommending that long ago, and some of it made things measurably worse.

Moving country makes this urgent rather than theoretical. You arrive and create fifteen new accounts in a month. A bank, a university portal, a transport card, a health insurer, a landlord's system, a phone provider. Each one wants a password, and each one is a door into something that matters. You will make these decisions quickly, while tired, in a language that is not your first, and you will live with them for years.

Here is what genuinely protects an account, what never did, and how to manage the pile without losing your mind. The short version: length, uniqueness and a second factor. Everything after that is detail, and most of the detail people worry about turns out not to matter at all.

College Life is working with Bitdefender to help moved-abroad 18 to 35s keep their devices, data, money and identity safe while they live their whole lives online in a new country. In line with this mission, Bitdefender is providing College Life Club members with 50% off for young professionals and graduates, and a free-trial option for students. Become a member of College Life Club (free) to get this benefit right now.

Password Requirements That Actually Matter

Start with what the evidence supports. These are the rules that change whether an account survives an attack, in rough order of how much they matter.

The ordering is deliberate. If you act on the first two and nothing else, you have captured most of the available protection. The rest are refinements on top of a decision you have already got right.

Everything in this section is now mainstream guidance among the organisations that study this, which was not true a decade ago.

Length beats complexity, by a lot

Every extra character multiplies the work required to break a password. Every added symbol only adds a little. A long passphrase of ordinary words is stronger than a short string of punctuation, and far easier to remember. This is why the UK's national cyber body recommends three random words rather than the symbol soup people were taught. Aim for length first and stop optimising anything else. Four ordinary words you can picture together are easier to type on a phone than a symbol string, and stronger. That combination is why the advice changed.

Never reuse a password anywhere

Reuse is the single biggest cause of accounts being taken over. One site is breached, the list of email and password pairs gets traded, and every other account using that pair falls at once. Nothing else on this page matters if you reuse. A unique password per account is the rule that carries the most weight. Breached credential lists are traded in bulk and tested automatically against hundreds of services. The attack costs nothing and runs while you sleep, which is why one reused pair is enough.

Uniqueness matters most where it hurts

If you cannot make everything unique immediately, start with email, banking and anything holding your identity documents. Email is the master key, because it can reset almost everything else. Protecting it properly is worth more than protecting ten minor accounts. Work outwards from there. Email, then money, then anything holding your passport or visa, then everything else in whatever order you get to it.

Turn on two-factor authentication

A second factor means a stolen password alone is not enough. It is the largest single improvement available after uniqueness, and most services now offer it free. Enable it on email and banking today, and on everything else as you go. The friction is smaller than people expect. Most services only ask for the second factor on a new device, so day to day you will barely notice it.

Prefer an app over SMS for codes

Text messages can be intercepted, and moving country makes it worse, because a lost or swapped number breaks the link entirely. An authenticator app or a hardware key is steadier. This matters more for anyone who will change phone numbers within the year. Moving country almost always means a new number. Anything tied to the old one becomes unreachable at exactly the moment you need it, which is a genuinely common way people lose accounts.

Do not make it about you

Names, birthdays, your city, your football team and your pet are all in your public footprint. Anything guessable from your social accounts is not a secret. Random beats meaningful every time. The same applies to the pattern rather than the content. A word plus a year plus an exclamation mark is a shape attackers test first, whatever words you put in it.

Change a password when there is a reason

Change it when a service is breached, when you suspect exposure, or when you shared it. Not on a schedule. Scheduled changes push people towards small predictable edits, which is the opposite of what was intended. Breach notification services tell you when a site you use has been exposed. That turns this from a calendar habit into a response to something real.

Password Advice That Made Things Worse

Some widely taught rules actively reduced security. They persist because organisations copied each other, and because bad rules look responsible.

That last point is the reason they survive. A rule that visibly inconveniences people looks like it is doing something, and nobody gets criticised for demanding a symbol. Being seen to try is easier to defend than being effective.

Recognising these matters, because several still appear on sign-up forms today and quietly shape what people choose.

Forced monthly rotation

Making people change passwords every thirty days produced predictable patterns: the same word with an incrementing number on the end. The current standards, including the widely cited NIST guidance, advise against arbitrary expiry for exactly this reason. Rotation without cause trains bad habits. If a service forces you to change anyway, change it properly rather than incrementing a number. A manager makes that painless, which is the practical answer to a rule you cannot switch off.

Mandatory symbol and case rules

Requiring one uppercase, one number and one symbol produces predictable placement. The capital goes first, the number and symbol go last. Attackers know this because everyone does the same thing, so the added complexity is far smaller than it looks. The rule also pushes people towards shorter passwords, because a complicated one is harder to remember. It traded the thing that works for the thing that looks rigorous.

Short maximum lengths

Any site capping passwords at twelve or sixteen characters is limiting your strongest defence. Worse, a low cap sometimes hints the password is being stored badly. You cannot fix this yourself; use the maximum allowed and make certain that account has two-factor enabled. A site that also blocks spaces or common symbols is worth noting. Those restrictions usually point at old systems behind the login page.

Security questions as a second factor

Your mother's maiden name and your first school are findable, and in an era of public profiles they are close to public knowledge. Where a service insists, answer with a random string stored in your manager rather than the truth. Record which nonsense answer went with which question. An answer you cannot reproduce is as much a lockout risk as a forgotten password.

Password hints

A hint that means something to you usually means something to anyone who has read your profile. Skip the field where you can, and fill it with nonsense where it is required. Hints are visible before authentication on many systems, which means they are offered to anyone who reaches the login page.

Writing it down being always wrong

A password written on paper in your own home is a smaller risk than the same weak password reused across forty sites. Paper does not get breached remotely. This is not the ideal system, but the blanket rule was always too simple. The real rule is about your threat. A note in a drawer at home is fine. The same note on a shared desk in an open-plan office is not.

Managing Accounts Across Two Countries

This is the part that actually breaks after a move, and it is rarely covered. You now have two lives' worth of accounts, in two countries, sometimes in two languages.

The pile is the problem. Nobody manages forty unique long passwords by memory, and pretending otherwise is how reuse creeps back in.

The honest version is that everyone reuses until they stop trying to remember. It is not a discipline failure, it is an impossible task, and the fix is a tool rather than more willpower.

Use a password manager

One tool generates, stores and fills unique passwords for everything. It is the only approach that makes uniqueness realistic at forty accounts. It also solves the second problem nobody mentions, which is filling. A manager types the password into the right site only, so a convincing fake page gets nothing. Bitdefender SecurePass is included on the member plan. That matters, because a manager you pay for separately is the one people postpone and never set up.

Make the master password excellent

The manager's own password is the one thing you memorise, so give it real length. Three or four random words, never used anywhere else, never typed into anything but the manager itself. Write it down once while you learn it, keep the paper somewhere private, and destroy it after a fortnight of typing it from memory.

Keep recovery routes that survive a move

Recovery codes, backup email and recovery phone numbers all break when you change country. Download recovery codes and store them somewhere that is not your phone, before the number changes. Do this in the week before you fly, not after you arrive. Once the old number stops working, some services have no route back at all.

Audit your old-country accounts

The accounts you set up at eighteen are usually the weakest and the most reused. Old email providers, forums, shopping sites. Work through them once, closing what you no longer need and fixing what you keep. An afternoon is usually enough. Start with whichever email address you used at school, because that is the one everything else was registered against.

Protect the accounts that hold your documents

Setting up abroad means uploading a passport, a visa letter and a bank statement to various portals. Our banking guide covers setting up online banking properly; the account itself deserves the same care as the money in it. Banking apps also tend to offer the strongest second-factor options available to you, so they are a good place to start the habit.

Watch your professional accounts

Your professional profile is how employers reach you, and it carries your history. Building an online presence is standard advice for a job hunt, and an account that visible needs a unique password and a second factor. A compromised professional profile is used to message your contacts, which turns your credibility into someone else's tool.

Keep work and personal accounts apart

Using one password across a personal email and a work login means a breach at either end reaches both. Employers also lose access when you leave, sometimes abruptly, and anything personal tied to that account goes with it. Keep the two sets separate from the first week, because untangling them later is far more work than starting cleanly.

Do not share credentials with flatmates

Streaming logins get shared, then reused elsewhere, then leaked when someone's other account is breached. Use the household or profile features services provide, rather than passing a password around a group chat. Group chats are searchable and they outlive the flatshare. A password shared in one is effectively permanent.

Password Requirements for the Accounts That Matter Most

Not every account deserves equal effort. Spending your attention where the damage would be worst is the sensible version of this advice.

Work down this order. If you only ever act on one section of this article, make it this one.

Most accounts genuinely do not matter. A forum you posted on twice, a shop you used once. Spending equal effort everywhere is why people give up, so decide what is worth protecting and let the rest be ordinary.

Email first, always

Email resets everything else, which makes it the account that protects all the others. Longest password, strongest second factor, and no reuse anywhere. Treat a compromise here as an emergency rather than an inconvenience. If you suspect it, change the password, sign out all sessions and check the forwarding rules. Quiet forwarding is how an intruder keeps reading after you have locked them out.

Banking and payment accounts

Money is the obvious target. Enable every protection the bank offers, including transaction notifications, so you learn about a problem in minutes rather than at the end of the month. Small test transactions are a common first move, precisely because they are easy to miss on a statement. Keep banking setup details out of chat messages and email attachments.

Government and visa portals

Immigration systems hold your status, which is harder to replace than money. Losing access at the wrong moment can affect a permit renewal, and support queues in a second language are slow. Keep the recovery details for these somewhere you can reach without the account itself, which is the situation you will actually be in.

University and employer systems

These carry your coursework, your payroll details and often your identity documents. They are also frequently targeted, because student and staff accounts are numerous and unevenly protected. Institutions rarely force good practice on students, so the account is usually only as strong as you decided to make it in your first week.

Cloud storage and photos

Everything you have scanned, photographed or backed up lives here, including documents you uploaded during applications. It is the single richest account for anyone building a picture of you. Check what is actually in there once. Most people find scanned documents they uploaded years ago and forgot were still stored.

Anything holding your address

Delivery accounts, transport cards and subscription services all hold where you live, which is worth more to someone than it looks. Combined with a name and a date of birth it is often enough to open something in your name. Treat these as ordinary rather than trivial.

The accounts you forgot

Old shopping accounts hold saved cards and addresses. Close what you do not use. An account that does not exist cannot be breached, and closing is faster than securing. Deletion is a legal right in Europe, and most services now have a working process for it even when it is buried in the settings.

Conclusion

The genuine password requirements are short. Make them long, make every one different, and put a second factor on anything that matters. Everything else is detail.

The old advice, symbols in fixed positions and monthly changes, made passwords harder for people and barely harder for attackers. Dropping it is not a shortcut, it is the current guidance from the people who study this properly.

The practical version, once you have accounts in two countries, is a manager plus one excellent master password. That combination is what makes uniqueness survivable at forty accounts rather than an aspiration you abandon in the second week.

If you do nothing else after reading this, do two things. Put a unique long password on your email and switch on a second factor there. That single account controls the recovery route for almost everything else you own, and securing it takes about five minutes.

Everything else on this page can wait for a quiet evening. That one cannot, because it is the account an attacker would go for first.

The purpose of this guide was to help moved-abroad 18 to 35s keep their devices, data, money and identity safe while they live their whole lives online in a new country. To help you on this journey, College Life has partnered with Bitdefender to make your life easier. Join College Life Club for free and start taking advantage of this today.

Frequently Asked Questions

What are the real password requirements for a strong password?

Length first, uniqueness second, and a second factor on anything important. A long passphrase of ordinary words beats a short string of symbols. Using it on only one account matters more than how it is composed.

Are passwords case sensitive?

Almost always, yes. Capital and lowercase letters count as different characters on nearly every modern service. That is worth knowing when a login fails and you are certain the password is right.

Should I change my passwords regularly?

Only when there is a reason: a breach, a suspicion, or a password you shared. Scheduled changes push people towards predictable small edits, which is why current guidance advises against arbitrary expiry.

Is a password manager safe?

Safer than the alternative, which for most people is reuse. It concentrates risk into one well-defended place instead of spreading weak passwords across forty sites, and it makes uniqueness practical rather than theoretical.

The objection people raise is the single point of failure. That is real, and it is why the master password and its second factor matter more than any other credential you own. In exchange you stop having thirty weak points.

What should I do if a site limits my password length?

Use the longest it allows and enable two-factor authentication on that account. A low cap is a limitation you cannot fix from your side, so add protection at the layer you control.

What are you waiting for? Join the community today.

Create a profile

About the authors

Written by Kristian Voldrich

Reviewed by Ohad Gilad

Fact Checked by Ohad Gilad


Related articles

View more