Opinion: Passwords as a concept are completely broken
One of my pet dislikes in this industry is the way we handle passwords. I’ve thought that, as a concept, they are completely broken and have been for a long time.
We tell users:
- Pick something really complex
- Don’t write it down
- Change it regularly
- Use a different password for each site, and often for each role that you hold in each site
- Deal with the fact that we apply different rules for passwords on each site
etc, etc.
2026-04-16