Three random words better than more complex passwords – GCHQ

7 August 2021, 07:14

Man uses a laptop
Online Safety Bill. Picture: PA

The advice comes amid rising cyber crime amid the pandemic.

It is far better to concoct passwords made up of three random words than use more complex variations involving streams of letters, numbers and symbols, Government experts have said.

The National Cyber Security Centre (NCSC), part of Government Communications Headquarters (GCHQ), highlighted its “three random words” recommendation in a new blog post.

It said a key reason for using the system is it creates passwords that are easy to remember yet strong enough to keep online accounts secure from cyber criminals, owing to their unusual combination of letters.

By contrast, more complex passwords can be ineffective because they can be more guessable for criminals and the software they build to detect them, the advice says.

The agency says cyber criminals target predictable means supposed to make passwords more complex – like substituting the letter o with a zero, or the number one with an exclamation mark.

Criminals allow for such patterns in their hacking software, which negates any desired added security from such passwords.

“Counter-intuitively, the enforcement of these complexity requirements results in the creation of more predictable passwords,” the agency said.

By contrast, passwords constructed from three random words tended to be longer and harder to predict, and used letter combinations which were more difficult for hacking algorithms to detect.

The blog post concedes the three random words approach was not 100% safe since people might use predictable word combinations, but said a major advantage of the system was its usability “because security that’s not usable doesn’t work”.

Staff wellbeing
Cyber crime has risen dramatically during the pandemic (Joe Giddens/PA)

The guidance comes as cyber crime has soared during the pandemic, with online fraud rising 70% in the last year, according to data from the Office for National Statistics.

“Traditional password advice telling us to remember multiple complex passwords is simply daft,” NCSC technical director Dr Ian Levy says on the centre’s website.

“There are several good reasons why we decided on the three random words approach – not least because they create passwords which are both strong and easier to remember.

“By following this advice, people will be much less vulnerable to cyber criminals and I’d encourage people to think about the passwords they use on their important accounts, and consider a password manager.”

By Press Association

More Technology News

See more More Technology News

People walk by the Las Vegas Convention Centre

Smart home tech, AI and cars among central themes as CES 2025 prepares to open

Mark Zuckerberg

Meta criticised over ‘chilling’ content moderation changes

A mobile phone screen

Meta ends fact-checking on Facebook and Instagram in favour of community notes

An Apple phone

Apple to update AI tools after BBC complaint over inaccurate news alerts

Meta is ditching its fact-checking service

Meta ditches fact-checking on Facebook and Instagram in favour of X-style 'community notes'

A wallet with bank cards cash

35% of young adults ‘are concerned about their finances on a daily basis’

Broadcaster Cathy Newman at the Women of The Year Lunch and Awards 2019 in London

‘Haunting’ to see deepfake pornography of myself, says journalist Cathy Newman

A laptop user with their hood up

Ministers to crack down on deepfakes and sharing of illicit intimate images

Elvie Rise smart baby bouncer

British tech firm Elvie unveils smart baby bouncer

The phone maker first introduced its suite of generative AI tools a year ago (David Parry/PA)

More than four million people in the UK using Samsung Galaxy AI tools, firm says

Critics of AI have raised concerns about the technology's potential impact on the job market (Michael Dwyer/AP)

OpenAI is ready to focus on ‘superintelligence’, boss Sam Altman says

CES 2025 signage

CES ‘doesn’t have the same support’ from the UK as other nations, show boss says

Health Secretary Wes Streeting told MPs he believes in 'different courses for different horses' (PA)

Use of NHS app will ‘free up phone line’ for elderly lacking tech skills

CES 2025 Preview

CES 2025: AI-powered beauty mirrors and robot pets among gadgets on display

The firm said it would begin a pilot of the new system with a L'Oreal brand in stores in Asia later in 2025. (L'Oreal)

New L’Oreal skin analysis tool can help predict aging and cosmetic issues

Samsung's Vision AI smart assistant, which are built into Samsung's TVs to act as a virtual assistant

Samsung unveils plans to turn TVs into AI assistants