Curious Past All articles
Tech History

One Nervous Computer Scientist Invented Your Most Annoying Login Ritual

Curious Past
One Nervous Computer Scientist Invented Your Most Annoying Login Ritual

You've been there. You create a perfectly reasonable password, hit submit, and then a little red message appears: Must contain at least one uppercase letter, one number, and one special character. You groan, add a "1!" to the end of whatever word you already chose, and move on with your life. It feels like the internet has always worked this way.

It hasn't. Those maddening requirements were invented by one man, during one anxious decade, to solve a problem that may never have been as serious as he feared.

The Man Who Started It All

In 1972, a computer scientist named Robert Morris Sr. was working at Bell Labs, one of the most influential technology research centers in American history. Morris was brilliant — he would later go on to work for the National Security Agency — and he was deeply worried about something most people hadn't even begun to think about: what happens when someone guesses your password?

At the time, computers were enormous, expensive, and mostly operated by universities and government agencies. The idea that ordinary people would one day carry them in their pockets was pure science fiction. But Morris could already see that as computing expanded, unauthorized access would become a real threat. He began developing what became known as password hashing — a method of storing passwords in scrambled form so that even system administrators couldn't read them.

His work was foundational. But the rules that most of us actually feel every day — the complexity requirements, the mandatory symbols, the expiration timers — those came later, from a different set of hands.

The Eight-Page Document That Shaped the Internet

Fast forward to 2003. A researcher at the National Institute of Standards and Technology named Bill Burr was tasked with writing a guide for federal agencies on how to manage passwords securely. Burr wasn't working from deep empirical research. He was working from a limited set of older studies, some intuition, and a genuine desire to help.

The result was an eight-page document called NIST Special Publication 800-63. It recommended that passwords include uppercase letters, lowercase letters, numbers, and symbols. It also suggested that passwords be changed every 90 days. Federal agencies adopted it. Then corporations adopted it. Then every website on the internet, from your bank to your pizza delivery app, adopted it too.

For over a decade, those guidelines were treated as gospel.

The Problem Nobody Wanted to Admit

Here's the uncomfortable part of the story. By the mid-2000s, security researchers were quietly noticing something strange: the complexity rules weren't actually making passwords harder to crack. They were just making them harder to remember.

When people are forced to create complex passwords, they don't invent something genuinely random. They do something very human — they take a word they already know and modify it in the most predictable way possible. "Password" becomes "P@ssw0rd." "Football" becomes "F00tb@ll1." Hackers figured this out quickly. In fact, automated cracking tools are specifically programmed to test those common substitutions first.

Worse, the 90-day expiration rule backfired spectacularly. When people know they'll have to change their password in three months, they don't create a brand-new strong one. They create a weak one that's easy to iterate — "Spring2024," "Summer2024," "Fall2024." Security researchers call this pattern walking, and it's one of the most exploitable habits in digital security.

The Moment the Rulebook Got Rewritten

In 2017, something remarkable happened. NIST rewrote its own guidelines — and essentially reversed course on almost everything Burr had recommended. The new guidance said agencies and organizations should stop requiring complex character combinations. It said mandatory periodic password changes should be dropped unless there's evidence of a breach. It recommended focusing instead on password length, since a long, simple phrase is statistically harder to crack than a short, jumbled mess of characters.

Bill Burr, by then retired, gave an interview to the Wall Street Journal in which he said he regretted writing the original document. He admitted the advice was largely based on a paper from the 1980s and that he didn't have the data to back up what became two decades of universal policy.

It was a remarkable moment of institutional honesty — and almost nobody outside the cybersecurity world noticed.

Why We're Still Living With the Old Rules

Despite the updated guidelines, the vast majority of websites and apps still enforce the old complexity requirements. Your gym's membership portal. Your local library card login. Your airline rewards account. They're all still running on rules that the organization that invented them has since walked back.

The reason is almost embarrassingly simple: updating login systems costs money, requires developer time, and creates legal liability questions that companies don't want to touch. It's easier to keep the old rules in place and let users keep suffering.

There's also a psychological dimension to it. Complex password requirements feel secure. They look serious. A login page that asks for a 20-character phrase with no symbols seems less rigorous than one demanding a mix of cases and punctuation — even if the opposite is technically true.

The Bigger Lesson

The story of password requirements is really a story about how one person's best guess, made under institutional pressure and limited data, can calcify into permanent infrastructure that outlasts anyone's ability to question it.

Robert Morris Sr. was trying to protect something genuinely important. Bill Burr was trying to do his job carefully. Neither of them could have predicted that their work would define the daily digital experience of hundreds of millions of people for decades.

Next time you're forced to reset a password and you mutter something unkind at your screen, remember: you're not just annoyed at a website. You're living inside a 1970s security scare that never quite ended.

All Articles

Related Articles

Movie Theaters Once Tried to Ban Popcorn — Now It's the Snack That Owns Your Living Room

Movie Theaters Once Tried to Ban Popcorn — Now It's the Snack That Owns Your Living Room

The Cereal Box Lie That Turned Americans Into Food Paranoids

The Cereal Box Lie That Turned Americans Into Food Paranoids

Three Notes, One Mistake: The Accidental Chime That America Never Stopped Hearing

Three Notes, One Mistake: The Accidental Chime That America Never Stopped Hearing