Uppercase, number, symbol — the complexity rules you learned in 2009 are not how password security actually works. Here's the math, the attack mechanics, and what actually protects you.
The password policy that defined a generation of IT security requirements — at least 8 characters, one uppercase, one number, one symbol — was based on a 2003 NIST publication that its own author, Bill Burr, later said he regretted writing. NIST formally reversed the guidance in 2017. The recommendation now is length over complexity, no forced periodic rotation, and no composition rules that predictably reduce entropy.
The reason complexity rules fail is predictable human behaviour. Given the rule "must contain uppercase, number, and symbol," users don't generate random strings. They capitalise the first letter, put the number at the end, and append an exclamation mark. Password1! satisfies the complexity rule. A modern cracking rig cracks it in milliseconds.
Password1!
Bit entropy is a measure of how many possible values a password could take. A password drawn uniformly at random from a character set of size N with length L has entropy of L × log₂(N) bits.
Character sets and their approximate log₂(N):
An 8-character password using the full 95-character set has ~52.6 bits of entropy. That sounds substantial. The problem is that real passwords are not drawn uniformly at random from the full character set — they're drawn from the far smaller space of strings that humans find memorable.
Password cracking doesn't start at A, iterate through every possible combination, and end at Z. That's brute force — it's slow, it's predictable, and serious cracking operations abandoned it as the primary method years ago.
Modern dictionary attacks layer multiple strategies in order of probability:
password
Season + Year!
CityName + digits
PetName + birthday
A P@ssw0rd variant cracks in the first few minutes of a targeted attack. The technical entropy is irrelevant — the *effective* entropy of the word "password" with predictable substitutions is close to zero.
P@ssw0rd
A correctly random 12-character lowercase password has about 56 bits of entropy and is dramatically more resistant to cracking than P@ssw0rd1!. But more practically: a random 5-word passphrase drawn from a list of 7,776 common English words (the Diceware method) has log₂(7776⁵) ≈ 64.6 bits of entropy. It's also memorable, fast to type, and doesn't require substitution tricks that reduce effective entropy.
P@ssw0rd1!
The comparison that matters:
Tr0ub4dor&3
correct horse battery staple
The passphrase is stronger, more typeable, and doesn't tempt the user to reuse it across sites.
Individual password strength is one factor. Reuse multiplies every breach you've ever been in across every other account that shares the password. Credential stuffing — taking a breached username/password pair and trying it at hundreds of other services — is automated, fast, and wildly successful at scale because password reuse is endemic.
The attack math is asymmetric. One breach at a low-security forum from 2018 can compromise your email, which leads to password reset of your bank, which leads to financial loss — all because you reused a password. Individual password strength is secondary to individual password uniqueness.
The complexity rules persist in corporate environments because policy change is slow and audit frameworks still reference the old NIST guidance. If you're forced to use them, use a password manager to generate random strings that satisfy the rules — and don't try to make them memorable. Memorability and randomness work against each other.