English

Text & everyday tools · Password Generator

A short history of password advice, from 1979 Unix to NIST 2017

· Background

passwords security-history source-discipline

An unsupported timeline fading into a verified present-day generator specification
Original ToolAcre vector illustration

From Morris and Thompson's 1979 study of Unix passwords through the era of complexity rules and forced resets to the 2017 NIST revision, this post explains how advice changed and why passphrases came out ahead.

Forty years of contradictory rules — why your bank, your employer and your email provider disagree

Banks, employers and email providers can impose different password rules, but explaining how every rule developed requires historical and policy evidence. The Password Generator repository contains current product code, tests and provenance records, not a four-decade archive. This article therefore corrects the timeline outline instead of laundering dates through confident prose.

The useful outcome is a source boundary readers can trust. Present-day ToolAcre behavior is documented precisely. Historical claims are marked as omitted until primary materials are verified. That is better than turning a current generator into authority over every past standard.

Contradictory password rules exist, but this repository is not a history source

The outline attributes findings and the beginning of salting to a 1979 paper. That paper is not included or cited by the product sources, so its conclusions, authorship context and technical claims are not paraphrased here. A title and year in a workbook are not sufficient evidence.

Readers interested in that milestone should consult the primary publication and relevant system history directly. ToolAcre’s implementation neither uses that paper nor exposes Unix password storage, making a detailed summary unrelated to what the code can verify.

The 1979 account is omitted without a cited primary source

The proposed account of dictionary attacks, cracking tools, composition rules and expiry across the 1980s and 1990s likewise needs archival sources. None appears in the generator package. Reconstructing a sequence from general memory would risk wrong dates, scope and causal claims.

What the current source can establish is that ToolAcre does not evaluate human patterns. It generates from explicit pools. That present behavior should not be presented as proof of why policies changed decades earlier.

The 1980s and 1990s account is omitted without archival evidence

Password-manager adoption, breach growth and pushback against complexity rules are external social and industry histories. The repository has no datasets or contemporary guidance documenting them. This section records that omission rather than inventing a trend line.

The product itself also is not a manager. It has no vault, sync, autofill or storage. Even a well-sourced manager history would need to preserve that distinction instead of implying ToolAcre participates in those functions.

The 2000s account is omitted rather than reconstructed from memory

A widely known comic may have influenced public conversation, but popularity is not a standards citation and its specific entropy claims are not source material here. The existing Diceware article already covers verified list arithmetic without using a cultural reference as normative authority.

ToolAcre’s passphrase mode should be evaluated through its own word files, uniform selection and current settings. A public four-word phrase must never be reused as a secret, regardless of how memorable its origin story is.

The 2011 comic is not used as a standards source here

The outline summarizes a 2017 NIST publication, but no copy or verified URL is among the repository sources for this article. The security traps explicitly forbid standards citations from memory. Accordingly, claims about length, composition, rotation and screening are omitted.

Policy writers should read the current primary standard and their organisation’s approved interpretation. ToolAcre’s option table can then implement compatible generation settings, but the generator does not confer compliance or interpret normative text.

The 2017 standards summary is omitted without the standard in the repository

Passkeys and a possible future beyond passwords involve protocols, devices and account ecosystems outside this tool. They are not treated as an ending to a history the article cannot source. A generator’s existence does not establish the adoption or security properties of replacements.

The same rule applies to multifactor authentication and federation. Those topics may be important, but adding them without authoritative materials would expand an already unsupported chronology rather than improve it.

The takeaway — the advice converged on long, random and memorable, which is exactly what the Password Generator produces

The repository-supported present is specific: three verified English EFF assets, cryptographic browser bytes, unbiased bounded draws, clear limits, one current DOM value, no analytics or ads, no stored history and no weak fallback. Those facts are enough for a useful product article.

A real history should be authored later from primary papers, standards editions and archives. Until then, do not claim that advice “converged” on one universal answer. Use ToolAcre for the local generation behavior it ships, while keeping policy and history sourced elsewhere.