Privacy and security
Passwords, passkeys and account security
The US federal standard now bans forced password rotation and composition rules, and every figure on passkey and MFA uptake comes from an interested party.
The rules most people were taught about passwords have been formally withdrawn. NIST Special Publication 800-63B, Revision 4, now tells the systems that verify passwords that they must not force periodic changes and must not impose composition rules such as requiring mixed character types. It raises minimum length substantially and requires that password managers be permitted. That is a normative standard, not a measured outcome: it binds US federal systems and reflects expert judgement, but nobody has published a study of what happened to breach rates in organisations that dropped rotation. Everything else in this area is worse evidenced still. Every figure on passkey uptake, password manager use and multi-factor effectiveness comes from a company or consortium that sells or promotes the thing being counted. For a concrete commercial example of the monitoring category discussed here, see remote employee monitoring software.
The standard reversed the advice most people were given
Forced ninety-day changes and the demand for a capital letter, a digit and a symbol are not merely optional now — the current revision tells verifiers not to do them.
SP 800-63B Revision 4 requires that verifiers "SHALL NOT require subscribers to change passwords periodically" and "SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types)".
Direction: Decrease. Strength of evidence: Strong.
Caveat Normative guidance for federal systems, not a measured outcome; forced rotation is still mandated by other frameworks such as PCI DSS in some configurations.
Length replaced complexity
The reasoning behind the reversal is that composition rules push people towards predictable substitutions while adding little entropy, and that length is what matters.
NIST Revision 4 raises the minimum length for single-factor passwords to 15 characters, 8 where the password is one factor of MFA, and recommends supporting at least 64 characters.
Direction: Increase. Strength of evidence: Strong.
Caveat A large tightening from Revision 3's 8-character minimum, and adoption by real services is not measured systematically anywhere.
SP 800-63B Revision 4 requires verifiers to screen new passwords against a blocklist of known-compromised passwords, bans password hints and knowledge-based authentication, and requires that password managers and autofill be allowed.
Direction: Increase. Strength of evidence: Strong.
Caveat "SHALL allow the use of password managers" is a requirement on verifiers, not evidence that password managers are effective — the two are routinely conflated.
Read as guidance, that is a coherent instruction set: long passphrases, screened against known-breached lists, never rotated on a calendar, stored in a manager. It carries weight because a standards body with no product to sell wrote it down and published its reasoning. It is not a claim about measured outcomes, because the outcome study does not exist.
MFA works, and the numbers come from the companies selling it
Multi-factor authentication is the one control with a large published effect. The problem is its provenance.
MFA reduced account compromise risk by 99.22% overall and by 98.56% for accounts with leaked credentials, with over 99.99% of MFA-enabled accounts remaining secure during the observation period.
Direction: Decrease. Strength of evidence: Mixed.
Caveat Commercially interested — authored by Microsoft from Microsoft's own product telemetry, with no random assignment, so security-conscious organisations selecting into MFA inflates the effect.
Selection bias is the difficulty. Organisations that turn MFA on differ from those that do not in every respect affecting compromise, so a telemetry comparison cannot separate the control from the customer. The direction of the effect is almost certainly right and the magnitude almost certainly overstated. The ubiquitous "MFA blocks 99.9% of attacks" line is a separate and weaker artefact: it traces to a 2019 Microsoft corporate blog post, not a study.
Nobody independent has counted passkey or password manager use
Passkeys are the intended replacement for passwords. The only global adoption figures come from the industry body that created them.
90% of consumers surveyed were aware of passkeys and 75% said they had enabled them on at least some accounts, while 68% of organisations were deploying, piloting or rolling out passkeys.
Direction: Increase. Strength of evidence: Weak.
Caveat Commercially interested — FIDO Alliance created passkeys — and respondents self-report on a technology many cannot distinguish from ordinary biometric sign-in, so 75% "enabled" is almost certainly a large overstatement.
The password manager picture has the same defect from the opposite direction: the most-cited survey of security behaviour is co-produced with a security-awareness vendor whose product addresses the shortfalls the survey reports.
41% of surveyed adults say they never use a password manager, and only 41% use MFA regularly despite 77% being aware of it.
Direction: Decrease. Strength of evidence: Mixed.
Caveat Commercially interested — co-produced with CybSafe, a security-awareness training vendor — and all figures are self-reported through an online panel.
One number here is not vendor-sourced. The UK's accredited official statistics found 47% of businesses and 38% of charities had two-factor authentication deployed in 2025/26 (DSIT, 2026), from a random probability sample, though "deployed" is not defined as universal enforcement.
Credentials feature in more breaches than they start
The most misquoted statistic in this area is the share of breaches involving credentials. Verizon's 2026 report puts credential abuse in 39% of breaches across all attack stages, but stolen credentials as the initial access vector in only 13% (Verizon Business, 2026) — a vendor-published convenience sample, and one whose two figures are regularly merged into a claim that credentials start most breaches. They do not. That distinction matters when weighing account controls against the patching and supplier exposure that dominate breach reports, or against the lure-driven clicking that no training reliably prevents.
The human cost is measured only in attitude. Pew found 70% of US adults feel overwhelmed by the number of passwords they must track and 45% feel anxious about whether their passwords are strong enough (Pew Research Center, 2023), from a probability sample of 5,101 adults now three years old.
The short version
- NIST SP 800-63B Revision 4 instructs verifiers not to force periodic password changes and not to impose character composition rules.
- The same revision raises the single-factor minimum length to 15 characters and requires screening against known-compromised password lists.
- NIST is a normative standard reflecting expert judgement, not a measured outcome, and no published study tracks breach rates in organisations that adopted it.
- Microsoft's telemetry study reports MFA cutting compromise risk by 99.22%, but Microsoft authored it from its own product data with no random assignment (2023).
- Every published figure on passkey and password manager uptake comes from an organisation that sells or promotes the technology, so real adoption is effectively unmeasured.